Clarify lab UME TLS verify after default flipped to true.

Point .env.example at NETX_UME_VERIFY_TLS=false for self-signed UME and surface the same hint on certificate verify login failures.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-08-06 15:11:21 +08:00
parent 20c2fcd496
commit 0ebf137776
2 changed files with 13 additions and 3 deletions

View file

@ -37,8 +37,8 @@ NETX_UME_ALARM_WS_ENABLED=true
NETX_UME_NOTIFICATION_ESTABLISH_PATH=/restconf/operations/zte-notifications:establish-subscription
NETX_UME_NOTIFICATION_DELETE_PATH=/restconf/operations/zte-notifications:delete-subscription
NETX_UME_NOTIFICATION_TOPIC=ALARM
# TLS verify for UME (default true). Set false only for lab self-signed certs.
# NETX_UME_VERIFY_TLS=true
# TLS verify for UME (default true). Lab self-signed UME must set false explicitly:
NETX_UME_VERIFY_TLS=false
# Auth (lab defaults: admin/admin123 + data/auth/mcp_token)
# NETX_AUTH_ENABLED=true
# Leave NETX_AUTH_SECRET empty to auto-create data/auth/jwt_secret on first boot.

View file

@ -305,7 +305,17 @@ class UMEClient:
self._lock_releaser()
except Exception:
pass
raise RuntimeError(f"ume_login_failed:{str(exc)[:240]}") from exc
detail = str(exc)[:240]
if self.verify_tls and (
"CERTIFICATE_VERIFY_FAILED" in detail
or "certificate verify failed" in detail.lower()
or "SSLCertVerificationError" in type(exc).__name__
):
detail = (
f"{detail} (hint: set NETX_UME_VERIFY_TLS=false for lab "
"self-signed UME, or pin a CA; restart API after change)"
)
raise RuntimeError(f"ume_login_failed:{detail}") from exc
token, ttl = self._extract_token_and_ttl(data)
if not token: