Treat thumbprint handling the same way as VDDK
This commit is contained in:
@@ -145,11 +145,21 @@ def connect_vim(
|
|||||||
password: VIM password.
|
password: VIM password.
|
||||||
port: HTTPS port, usually 443.
|
port: HTTPS port, usually 443.
|
||||||
thumbprint: Optional SHA-1 SSL thumbprint of the management endpoint.
|
thumbprint: Optional SHA-1 SSL thumbprint of the management endpoint.
|
||||||
|
When set, the peer certificate is pinned to this digest and the
|
||||||
|
system CA store is not used. pyVmomi's version-discovery GET
|
||||||
|
does not pin, so a self-signed vCenter fails CA verification
|
||||||
|
before SOAP login unless that handshake is skipped after the
|
||||||
|
pin check.
|
||||||
allow_untrusted: If True, skip certificate validation.
|
allow_untrusted: If True, skip certificate validation.
|
||||||
"""
|
"""
|
||||||
ssl_context = None
|
if thumbprint and not allow_untrusted:
|
||||||
if allow_untrusted:
|
peer = get_ssl_cert_thumbprint(host, port)
|
||||||
ssl_context = _ssl_client_context(verify=False)
|
if _normalize_thumbprint(peer) != _normalize_thumbprint(thumbprint):
|
||||||
|
raise ConnectionError(
|
||||||
|
f"management SSL thumbprint mismatch: got {peer}, expected {thumbprint}"
|
||||||
|
)
|
||||||
|
skip_ca = allow_untrusted or bool(thumbprint)
|
||||||
|
ssl_context = _ssl_client_context(verify=False) if skip_ca else None
|
||||||
return SmartConnect(
|
return SmartConnect(
|
||||||
host=host,
|
host=host,
|
||||||
user=username,
|
user=username,
|
||||||
@@ -157,7 +167,7 @@ def connect_vim(
|
|||||||
port=port,
|
port=port,
|
||||||
thumbprint=thumbprint,
|
thumbprint=thumbprint,
|
||||||
sslContext=ssl_context,
|
sslContext=ssl_context,
|
||||||
disableSslCertValidation=allow_untrusted,
|
disableSslCertValidation=skip_ca,
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -214,6 +214,8 @@ class VixDiskLibHandle:
|
|||||||
Args:
|
Args:
|
||||||
server_name: vCenter or ESXi hostname/IP.
|
server_name: vCenter or ESXi hostname/IP.
|
||||||
thumbprint: SHA-1 thumbprint of the management TLS certificate.
|
thumbprint: SHA-1 thumbprint of the management TLS certificate.
|
||||||
|
When set, the certificate is pinned and need not be in
|
||||||
|
the system CA store.
|
||||||
username: VIM user name.
|
username: VIM user name.
|
||||||
password: VIM password.
|
password: VIM password.
|
||||||
vmx_spec: VM selector, ``moref=vm-…``.
|
vmx_spec: VM selector, ``moref=vm-…``.
|
||||||
@@ -224,6 +226,8 @@ class VixDiskLibHandle:
|
|||||||
``nbdssl``.
|
``nbdssl``.
|
||||||
port: HTTPS port, usually 443.
|
port: HTTPS port, usually 443.
|
||||||
allow_untrusted: Skip management TLS verification when True.
|
allow_untrusted: Skip management TLS verification when True.
|
||||||
|
When False with no ``thumbprint``, the system CA store
|
||||||
|
is used.
|
||||||
"""
|
"""
|
||||||
LOG.debug(
|
LOG.debug(
|
||||||
"Connecting VixDiskLib: server_name=%s thumbprint=%s "
|
"Connecting VixDiskLib: server_name=%s thumbprint=%s "
|
||||||
|
|||||||
Reference in New Issue
Block a user