#!/bin/bash # # Check puppet fingerprints, hydractl perspective. # # Load source $APP_BASE/lib/hydra/functions || exit 1 hydra_config_load # Command line arguments BASENAME="`basename $0`" # Execute openssl function puppet_openssl { if [ -z "$1" ]; then return fi openssl x509 -text -noout -fingerprint -in $1 | grep "^SHA1 Fingerprint=" } # Master: # # openssl x509 -text -noout -fingerprint -in /var/lib/puppetmaster/ssl/ca/signed/fqdn.pem # openssl x509 -text -noout -fingerprint -in /var/lib/puppetmaster/ssl/certs/ca.pem # if [ -d "/var/lib/puppetmaster/ssl" ]; then if [ -d "/var/lib/puppetmaster/ssl/ca/signed" ]; then for file in `ls /var/lib/puppetmaster/ssl/ca/signed`; do fp="`puppet_openssl /var/lib/puppetmaster/ssl/ca/signed/$file`" echo "`basename $file .pem`: $fp" done fi if [ -f "/var/lib/puppetmaster/ssl/certs/ca.pem" ]; then echo "ca: `puppet_openssl /var/lib/puppetmaster/ssl/certs/ca.pem`" fi fi # Node: # # openssl x509 -text -noout -fingerprint -in /var/lib/puppet/ssl/certs/fqdn.pem # openssl x509 -text -noout -fingerprint -in /var/lib/puppet/ssl/certs/ca.pem # if [ -d "/var/lib/puppet/ssl" ]; then fqdn="`facter fqdn`" fp="`puppet_openssl /var/lib/puppet/ssl/certs/$fqdn.pem`" echo "$fqdn: $fp" echo "ca: `puppet_openssl /var/lib/puppet/ssl/certs/ca.pem`" fi