2
0
mirror of https://github.com/xcat2/confluent.git synced 2026-09-29 00:31:09 +00:00

Apply fingerprint match logic on recheck

On scan/snoop, we were ignoring if certificate already matched up.
Bring this logic to the recheck logic, so that things behave consistently.
This commit is contained in:
Jarrod Johnson
2017-05-30 10:50:31 -04:00
parent d25ac000f4
commit eb48f2c1f7
@@ -406,6 +406,16 @@ def _recheck_single_unknown(configmanager, mac):
return
nodename = get_nodename(configmanager, handler, info)
if nodename:
if handler.https_supported:
dp = configmanager.get_node_attributes([nodename],
('pubkeys.tls_hardwaremanager',))
lastfp = dp.get(nodename, {}).get('pubkeys.tls_hardwaremanager',
{}).get('value', None)
if util.cert_matches(lastfp, handler.https_cert):
info['nodename'] = nodename
known_nodes[nodename][info['hwaddr']] = info
info['discostatus'] = 'discovered'
return # already known, no need for more
eventlet.spawn_n(eval_node, configmanager, handler, info, nodename)