# Installing admin client key into chef-server

**URL:** <https://discourse.chef.io/t/installing-admin-client-key-into-chef-server/3497>\
**Category:** Chef Infra (archive)\
**Created:** [January 2, 2013, 10:23pm UTC](https://discourse.chef.io/t/installing-admin-client-key-into-chef-server/3497 "2013-01-02T22:23:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![andi\_abes](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@andi\_abes](https://discourse.chef.io/u/andi_abes)\
**Post date:** [January 2, 2013, 10:23pm UTC](https://discourse.chef.io/t/installing-admin-client-key-into-chef-server/3497/1 "2013-01-02T22:23:45Z")

</div>

is there a way to provide chef-server (opensource) a client certificate  
that it should trust as an admin?

Basically, I’m integrating an app that talks to chef-server. I want a  
simple way to bootstrap an authentication scheme between this app and  
chef-server, with minimal manual interactions required.

---

<div class="post-metadata">

**Author:** ![Ranjib](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/ranjib/32/1040_2.png) [@Ranjib](https://discourse.chef.io/u/Ranjib)\
**Post date:** [January 2, 2013, 11:08pm UTC](https://discourse.chef.io/t/installing-admin-client-key-into-chef-server/3497/2 "2013-01-02T23:08:15Z")

</div>

not directly. the api does not support adding predefined public keys.

which version you are running? If you are using couch you can use the chef  
apiclient lib to handcraft a apiclient object and invoke cdb\_save directly.  
Note that since couch is normally bound to local interface , you have to  
run the script in the same instance where couch is running.

I had a requirement to use the same pki system across openvpn, chef and  
ssh, as part of which i used this strategy. But i dont recommend this, as  
this wont work on chef 11 (and its dirty way to achieve this).

On Wed, Jan 2, 2013 at 2:23 PM, andi abes [andi.abes@gmail.com](mailto:andi.abes@gmail.com) wrote:

> is there a way to provide chef-server (opensource) a client certificate  
> that it should trust as an admin?
> 
> Basically, I'm integrating an app that talks to chef-server. I want a  
> simple way to bootstrap an authentication scheme between this app and  
> chef-server, with minimal manual interactions required.

---

<div class="post-metadata">

**Author:** ![Seth\_Falcon\_01](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/seth_falcon_01/32/429_2.png) [@Seth\_Falcon\_01](https://discourse.chef.io/u/Seth_Falcon_01)\
**Post date:** [January 7, 2013, 5:11am UTC](https://discourse.chef.io/t/installing-admin-client-key-into-chef-server/3497/3 "2013-01-07T05:11:07Z")

</div>

On Jan 2, 2013, at 3:08 PM, Ranjib Dey wrote:

> On Wed, Jan 2, 2013 at 2:23 PM, andi abes [andi.abes@gmail.com](mailto:andi.abes@gmail.com) wrote:  
> is there a way to provide chef-server (opensource) a client certificate that it should trust as an admin?

In the Chef 11 Server, an admin client or user can create admin clients. In addition, in Chef 11, you can set the public\_key for a client as part of the create request. So if an integrating app provided a public\_key, a server admin could create an admin client that the app could use to authenticate with. Not sure if that's what you're looking for or not.

- seth

---

<div class="post-metadata">

**Author:** ![andi\_abes](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@andi\_abes](https://discourse.chef.io/u/andi_abes)\
**Post date:** [January 8, 2013, 4:42pm UTC](https://discourse.chef.io/t/installing-admin-client-key-into-chef-server/3497/4 "2013-01-08T16:42:30Z")

</div>

more or less... but I'm looking for it on chef 10 😉

On Mon, Jan 7, 2013 at 12:11 AM, Seth Falcon [seth@opscode.com](mailto:seth@opscode.com) wrote:

> On Jan 2, 2013, at 3:08 PM, Ranjib Dey wrote:
> 
> > On Wed, Jan 2, 2013 at 2:23 PM, andi abes [andi.abes@gmail.com](mailto:andi.abes@gmail.com) wrote:  
> > is there a way to provide chef-server (opensource) a client certificate  
> > that it should trust as an admin?
> 
> In the Chef 11 Server, an admin client or user can create admin clients.  
> In addition, in Chef 11, you can set the public\_key for a client as part of  
> the create request. So if an integrating app provided a public\_key, a  
> server admin could create an admin client that the app could use to  
> authenticate with. Not sure if that's what you're looking for or not.
> 
> - seth

---

<div class="post-metadata">

**Author:** ![kallistec](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/kallistec/32/23_2.png) [@kallistec](https://discourse.chef.io/u/kallistec)\
**Post date:** [January 8, 2013, 4:53pm UTC](https://discourse.chef.io/t/installing-admin-client-key-into-chef-server/3497/5 "2013-01-08T16:53:20Z")

</div>

On Tuesday, January 8, 2013 at 8:42 AM, andi abes wrote:

> more or less... but I'm looking for it on chef 10 😉

Is there a reason you're tied to this particular certificate? Even in the Chef 11 case you need to create the client from another admin user/client account, so that's either a manual step or you need another admin client key around to do the create operation.

--  
Daniel DeLeo

> On Mon, Jan 7, 2013 at 12:11 AM, Seth Falcon \<[seth@opscode.com](mailto:seth@opscode.com) ([mailto:seth@opscode.com](mailto:seth@opscode.com))\> wrote:
> 
> > On Jan 2, 2013, at 3:08 PM, Ranjib Dey wrote:
> > 
> > > On Wed, Jan 2, 2013 at 2:23 PM, andi abes \<[andi.abes@gmail.com](mailto:andi.abes@gmail.com) ([mailto:andi.abes@gmail.com](mailto:andi.abes@gmail.com))\> wrote:  
> > > is there a way to provide chef-server (opensource) a client certificate that it should trust as an admin?
> > 
> > In the Chef 11 Server, an admin client or user can create admin clients. In addition, in Chef 11, you can set the public\_key for a client as part of the create request. So if an integrating app provided a public\_key, a server admin could create an admin client that the app could use to authenticate with. Not sure if that's what you're looking for or not.
> > 
> > - seth
