diff --git a/confluent_server/confluent/config/attributes.py b/confluent_server/confluent/config/attributes.py index b408cb77..94ced984 100644 --- a/confluent_server/confluent/config/attributes.py +++ b/confluent_server/confluent/config/attributes.py @@ -136,12 +136,13 @@ node = { # }, 'discovery.policy': { 'description': 'Policy to use for auto-configuration of discovered ' - 'and identified nodes. Valid values are "manual" or ' - '"insecure". Default behavior is "manual". In manual,' - 'node discovery does not happen unless a client ' - 'explicitly approves. With insecure, automatic ' - 'discovery is allowed to proceed without proving the ' - 'validity of public key to a trusted peer.', + 'and identified nodes. Valid values are "manual", ' + '"permissive", or "open". "manual" means nodes are ' + 'detected, but not autoconfigured until a user ' + 'approves. "permissive" indicates to allow discovery, ' + 'so long as the node has no existing public key. ' + '"open" allows discovery even if a known public key ' + 'is already stored', }, 'location.room': { 'description': 'Room description for the node', diff --git a/confluent_server/confluent/discovery/core.py b/confluent_server/confluent/discovery/core.py index b8cf7cff..a413bd4f 100644 --- a/confluent_server/confluent/discovery/core.py +++ b/confluent_server/confluent/discovery/core.py @@ -190,6 +190,8 @@ def detected(info): return # For now, require hwaddr field to proceed # later, manual and CMM discovery may act on SN and/or UUID if info['hwaddr'] in known_nodes: + # we should tee these up for parsing when an enclosure comes up + # also when switch config parameters change, should discard return handler = None for service in info['services']: @@ -202,18 +204,24 @@ def detected(info): cfg = cfm.ConfigManager(None) handler = handler.NodeHandler(info, cfg) handler.probe() # unicast interrogation as possible to get more data + # for now, we search switch only, ideally we search cmm, smm, and switch + # concurrently nodename = macmap.find_node_by_mac(info['hwaddr'], cfg) if nodename: handler.preconfig() - if handler.discoverable_by_switch: - dp = cfg.get_node_attributes([nodename], ('discovery.policy',)) - print(repr(dp)) - - - - - - + if handler.discoverable_by_switch: + # we can and did discover by switch + dp = cfg.get_node_attributes([nodename], ('discovery.policy',)) + policy = dp.get(nodename, {}).get('discovery.policy', {}).get( + 'value', None) + # TODO(jjohnson2): permissive requires we guarantee storage of + # the pubkeys, which is deferred for a little bit + # Also, 'secure', when we have the needed infrastructure done + # in some product or another. + if policy == 'permissive': + fp = handler.https_cert + if policy == 'open': + handler.config() def start_detection(): diff --git a/confluent_server/confluent/discovery/handlers/generic.py b/confluent_server/confluent/discovery/handlers/generic.py index 92c5d5e2..692a78f1 100644 --- a/confluent_server/confluent/discovery/handlers/generic.py +++ b/confluent_server/confluent/discovery/handlers/generic.py @@ -12,10 +12,14 @@ # See the License for the specific language governing permissions and # limitations under the License. +import eventlet +webclient = eventlet.import_patched('pyghmi.util.webclient') +import hashlib class NodeHandler(object): def __init__(self, info, configmanager): + self._fp = None self.info = info self.configmanager = configmanager targsa = None @@ -39,4 +43,20 @@ class NodeHandler(object): @property def discoverable_by_switch(self): - return True \ No newline at end of file + return True + + def _savecert(self, certificate): + self._fp = 'sha512$' + hashlib.sha512(certificate).hexdigest() + return True + + @property + def https_cert(self): + if self._fp: + return self._fp + if ':' in self.ipaddr: + ip = '[{0}]'.format(self.ipaddr) + else: + ip = self.ipaddr + wc = webclient.SecureHTTPConnection(ip, verifycallback=self._savecert) + wc.connect() + return self._fp \ No newline at end of file diff --git a/confluent_server/confluent/discovery/handlers/xcc.py b/confluent_server/confluent/discovery/handlers/xcc.py index ba71755a..0a0482cd 100644 --- a/confluent_server/confluent/discovery/handlers/xcc.py +++ b/confluent_server/confluent/discovery/handlers/xcc.py @@ -27,12 +27,10 @@ class NodeHandler(bmchandler.NodeHandler): ipmicmd.xraw_command(netfn=0x3a, command=0xf1, data=(1,)) self.discoverable = False except pygexc.IpmiException as e: - # If the XCC can't do it, that's fine, it wasn't stark - print('TODO: MUST DISTINGUISH BETWEEN LOGIN FAILURE') - # if login failure, discoverable should alse be false - print(repr(e)) - print(repr(e.ipmicode)) - pass + if e.ipmicode != 193: + # Do not try to discover an XCC that can't be preconfigged + # can't tell 100% if it's safe to do + self.discoverable = False if ipmicmd: ipmicmd.ipmi_session.logout()