mirror of
https://github.com/xcat2/confluent.git
synced 2026-09-29 00:31:09 +00:00
Compare commits
5 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 9828ea5898 | |||
| 7bdf7afb80 | |||
| cd20a69eb6 | |||
| c3d14977f2 | |||
| 31d19e9398 |
@@ -209,14 +209,14 @@ node = {
|
||||
},
|
||||
'deployment.useinsecureprotocols': {
|
||||
'description': ('What phase(s) of boot are permitted to use insecure protocols '
|
||||
'(TFTP and HTTP without TLS. By default, HTTPS is allowed. However '
|
||||
'(TFTP and HTTP without TLS. By default, only HTTPS is used. However '
|
||||
'this is not compatible with most firmware in most scenarios. Using '
|
||||
'"firmware" as the setting will still use HTTPS after the initial download, '
|
||||
'though be aware that a successful compromise during the firmware phase '
|
||||
'though be aware that a successful attack during the firmware phase '
|
||||
'will negate future TLS protections. The value "always" will result in '
|
||||
'tftp/http being used for entire deployment. Note that ONIE does not '
|
||||
'support secure protocols, and in that case this setting must be "always" '
|
||||
'or "firmware"'),
|
||||
'tftp/http being used for most of the deployment. The value "never" will '
|
||||
'allow HTTPS only. Note that Ubuntu will still use HTTP without TLS for '
|
||||
'a phase of the installation process.'),
|
||||
'validlist': ('always', 'firmware', 'never'),
|
||||
},
|
||||
'discovery.passwordrules': {
|
||||
|
||||
@@ -1020,9 +1020,13 @@ def eval_node(cfg, handler, info, nodename, manual=False):
|
||||
if nl:
|
||||
# The candidate nodename is the head of a chain, we must
|
||||
# validate the smm certificate by the switch
|
||||
macmap.get_node_fingerprint(nodename, cfg)
|
||||
util.handler.cert_matches(fprint, handler.https_cert)
|
||||
return
|
||||
fprints = macmap.get_node_fingerprints(nodename, cfg)
|
||||
for fprint in fprints:
|
||||
if util.cert_matches(fprint[0], handler.https_cert):
|
||||
if not discover_node(cfg, handler, info,
|
||||
nodename, manual):
|
||||
pending_nodes[nodename] = info
|
||||
return
|
||||
if (info.get('maccount', False) and
|
||||
not handler.discoverable_by_switch(info['maccount'])):
|
||||
errorstr = 'The detected node {0} was detected using switch, ' \
|
||||
|
||||
@@ -441,7 +441,7 @@ def check_reply(node, info, packet, sock, cfg, reqview):
|
||||
return
|
||||
rqtype = packet[53][0]
|
||||
insecuremode = cfd.get(node, {}).get('deployment.useinsecureprotocols',
|
||||
'never')
|
||||
{}).get('value', 'never')
|
||||
if not insecuremode:
|
||||
insecuremode = 'never'
|
||||
if insecuremode == 'never' and not httpboot:
|
||||
|
||||
@@ -199,6 +199,7 @@ def _extract_neighbor_data_affluent(switch, user, password, cfm, lldpdata):
|
||||
'port': record['localport'],
|
||||
'peerid': peerid,
|
||||
}
|
||||
_extract_extended_desc(portdata, portdata['peerdescription'], True)
|
||||
_neighbypeerid[peerid] = portdata
|
||||
lldpdata[localport] = portdata
|
||||
neighdata[switch] = lldpdata
|
||||
|
||||
Reference in New Issue
Block a user