mirror of
https://github.com/xcat2/confluent.git
synced 2026-09-29 00:31:09 +00:00
Apply fingerprint match logic on recheck
On scan/snoop, we were ignoring if certificate already matched up. Bring this logic to the recheck logic, so that things behave consistently.
This commit is contained in:
@@ -406,6 +406,16 @@ def _recheck_single_unknown(configmanager, mac):
|
||||
return
|
||||
nodename = get_nodename(configmanager, handler, info)
|
||||
if nodename:
|
||||
if handler.https_supported:
|
||||
dp = configmanager.get_node_attributes([nodename],
|
||||
('pubkeys.tls_hardwaremanager',))
|
||||
lastfp = dp.get(nodename, {}).get('pubkeys.tls_hardwaremanager',
|
||||
{}).get('value', None)
|
||||
if util.cert_matches(lastfp, handler.https_cert):
|
||||
info['nodename'] = nodename
|
||||
known_nodes[nodename][info['hwaddr']] = info
|
||||
info['discostatus'] = 'discovered'
|
||||
return # already known, no need for more
|
||||
eventlet.spawn_n(eval_node, configmanager, handler, info, nodename)
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user