Treat thumbprint handling the same way as VDDK

This commit is contained in:
Lucian Petrut
2026-09-09 09:02:31 +00:00
parent 1e5b2d70a5
commit 070c372c50
2 changed files with 18 additions and 4 deletions
+14 -4
View File
@@ -145,11 +145,21 @@ def connect_vim(
password: VIM password. password: VIM password.
port: HTTPS port, usually 443. port: HTTPS port, usually 443.
thumbprint: Optional SHA-1 SSL thumbprint of the management endpoint. thumbprint: Optional SHA-1 SSL thumbprint of the management endpoint.
When set, the peer certificate is pinned to this digest and the
system CA store is not used. pyVmomi's version-discovery GET
does not pin, so a self-signed vCenter fails CA verification
before SOAP login unless that handshake is skipped after the
pin check.
allow_untrusted: If True, skip certificate validation. allow_untrusted: If True, skip certificate validation.
""" """
ssl_context = None if thumbprint and not allow_untrusted:
if allow_untrusted: peer = get_ssl_cert_thumbprint(host, port)
ssl_context = _ssl_client_context(verify=False) if _normalize_thumbprint(peer) != _normalize_thumbprint(thumbprint):
raise ConnectionError(
f"management SSL thumbprint mismatch: got {peer}, expected {thumbprint}"
)
skip_ca = allow_untrusted or bool(thumbprint)
ssl_context = _ssl_client_context(verify=False) if skip_ca else None
return SmartConnect( return SmartConnect(
host=host, host=host,
user=username, user=username,
@@ -157,7 +167,7 @@ def connect_vim(
port=port, port=port,
thumbprint=thumbprint, thumbprint=thumbprint,
sslContext=ssl_context, sslContext=ssl_context,
disableSslCertValidation=allow_untrusted, disableSslCertValidation=skip_ca,
) )
+4
View File
@@ -214,6 +214,8 @@ class VixDiskLibHandle:
Args: Args:
server_name: vCenter or ESXi hostname/IP. server_name: vCenter or ESXi hostname/IP.
thumbprint: SHA-1 thumbprint of the management TLS certificate. thumbprint: SHA-1 thumbprint of the management TLS certificate.
When set, the certificate is pinned and need not be in
the system CA store.
username: VIM user name. username: VIM user name.
password: VIM password. password: VIM password.
vmx_spec: VM selector, ``moref=vm-…``. vmx_spec: VM selector, ``moref=vm-…``.
@@ -224,6 +226,8 @@ class VixDiskLibHandle:
``nbdssl``. ``nbdssl``.
port: HTTPS port, usually 443. port: HTTPS port, usually 443.
allow_untrusted: Skip management TLS verification when True. allow_untrusted: Skip management TLS verification when True.
When False with no ``thumbprint``, the system CA store
is used.
""" """
LOG.debug( LOG.debug(
"Connecting VixDiskLib: server_name=%s thumbprint=%s " "Connecting VixDiskLib: server_name=%s thumbprint=%s "