From 070c372c50f89bc455bb55dc5ed0adbc922d17cf Mon Sep 17 00:00:00 2001 From: Lucian Petrut Date: Wed, 9 Sep 2026 09:02:29 +0000 Subject: [PATCH] Treat thumbprint handling the same way as VDDK --- openvixdisklib/nfc_auth.py | 18 ++++++++++++++---- openvixdisklib/openvixdisklib.py | 4 ++++ 2 files changed, 18 insertions(+), 4 deletions(-) diff --git a/openvixdisklib/nfc_auth.py b/openvixdisklib/nfc_auth.py index 75f4260..3f98cfa 100644 --- a/openvixdisklib/nfc_auth.py +++ b/openvixdisklib/nfc_auth.py @@ -145,11 +145,21 @@ def connect_vim( password: VIM password. port: HTTPS port, usually 443. thumbprint: Optional SHA-1 SSL thumbprint of the management endpoint. + When set, the peer certificate is pinned to this digest and the + system CA store is not used. pyVmomi's version-discovery GET + does not pin, so a self-signed vCenter fails CA verification + before SOAP login unless that handshake is skipped after the + pin check. allow_untrusted: If True, skip certificate validation. """ - ssl_context = None - if allow_untrusted: - ssl_context = _ssl_client_context(verify=False) + if thumbprint and not allow_untrusted: + peer = get_ssl_cert_thumbprint(host, port) + if _normalize_thumbprint(peer) != _normalize_thumbprint(thumbprint): + raise ConnectionError( + f"management SSL thumbprint mismatch: got {peer}, expected {thumbprint}" + ) + skip_ca = allow_untrusted or bool(thumbprint) + ssl_context = _ssl_client_context(verify=False) if skip_ca else None return SmartConnect( host=host, user=username, @@ -157,7 +167,7 @@ def connect_vim( port=port, thumbprint=thumbprint, sslContext=ssl_context, - disableSslCertValidation=allow_untrusted, + disableSslCertValidation=skip_ca, ) diff --git a/openvixdisklib/openvixdisklib.py b/openvixdisklib/openvixdisklib.py index 66dc906..9286782 100644 --- a/openvixdisklib/openvixdisklib.py +++ b/openvixdisklib/openvixdisklib.py @@ -214,6 +214,8 @@ class VixDiskLibHandle: Args: server_name: vCenter or ESXi hostname/IP. thumbprint: SHA-1 thumbprint of the management TLS certificate. + When set, the certificate is pinned and need not be in + the system CA store. username: VIM user name. password: VIM password. vmx_spec: VM selector, ``moref=vm-…``. @@ -224,6 +226,8 @@ class VixDiskLibHandle: ``nbdssl``. port: HTTPS port, usually 443. allow_untrusted: Skip management TLS verification when True. + When False with no ``thumbprint``, the system CA store + is used. """ LOG.debug( "Connecting VixDiskLib: server_name=%s thumbprint=%s "