Occasionally systems with incorrect hostnames will generate a certificate signing request on the puppet servers. Periodically clear these out on pupserver01-ec2-va with:
puppetserver ca list | awk '{print $1'} | xargs -n1 puppetserver ca clean --certname
Be careful to not specify --all which includes SIGNED certificates.
On the puppet CA server (currently pupserver01-ec2-va.apache.org) run
puppet node deactivate ooo-forums4-dev-vm puppet node clean ooo-forums4-dev-vm # remove node from ASF DNS
puppet node deactivate <hostname>
puppet node clean <hostname>
Signed certificates - ($vardir/ssl/ca/signed/node.domain.pem)
Cached facts - ($vardir/yaml/facts/node.domain.yaml)
Cached node objects - ($vardir/yaml/node/node.domain.yaml)
Reports - (puppetdb, datadog_reports)
on pupdb01-ec2-va run:
curl -X POST http://localhost:8080/pdb/query/v4/resources -H 'Content-Type:application/json' -d '{"query":["=","certname","iotdb-vm.apache.org"]}' | python3 -m json.tool | less