On Demand signing

Hi
What is the standard way of doing On-Demand CSR Signing?.

I am prefering send a request without ticket, but as per the docs what i understood is must manually approve it and sign them on the primary master.

I dont have direct master-agent connection here.

icinga2 --version
icinga2 - The Icinga 2 network monitoring daemon (version: 2.11.2-1)

Copyright © 2012-2020 Icinga GmbH (https://icinga.com/)
License GPLv2+: GNU GPL version 2 or later http://gnu.org/licenses/gpl2.html
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.

System information:
Platform: CentOS Linux
Platform version: 7 (Core)
Kernel: Linux
Kernel version: 3.10.0-1062.9.1.el7.x86_64
Architecture: x86_64

icinga2 ca list not showing anything on the master
Please support
Thanks

The signing request is sent to the parent node and finally at the master (as described here). As icinga2 ca list does not show anything there must be something wrong in your communication setup. I’d recommend to start digging the logs.

Thanks Roland for the reply
So through the satellites, the agent will communicate to master for generating the ca list correct?

“there must be something wrong in your communication setup. I’d recommend to start digging the logs.”

means i should check the satellites zones.conf and logs right?

yes.

I’d recommend to check every log of that chain means agent, satellite(s) and master.