9.1.11.1. Access EnforcementΒΆ

The Puppet Server uses a whitelist to determine which puppet clients can connect via the network. The certificate of the connecting client must match the fully qualified domain name of the system as resolved via DNS. If it does not then the connection is denied.

References: AC-3 : ACCESS ENFORCEMENT