Overview of a Puppet Split CA architecture (opens in new tab)
The Puppet Master CA is the only Certificate Authority (CA) in the whole infrastructure. It issues certificates for all Puppet agents. It also manages the Puppet Master systems. The Puppet Masters are only responsible for compiling catalogs requested by Puppet Agents - they don't act as CA themselves. They only accept Puppet Agents which certificates have been issued by the Puppet Master CA. The Puppet Agent retrieves their certificates from the Puppet Master CA the first time they run. They ...
Read the original article