diff --git a/.env.example b/.env.example index efabeee..c1012c9 100644 --- a/.env.example +++ b/.env.example @@ -37,8 +37,8 @@ NETX_UME_ALARM_WS_ENABLED=true NETX_UME_NOTIFICATION_ESTABLISH_PATH=/restconf/operations/zte-notifications:establish-subscription NETX_UME_NOTIFICATION_DELETE_PATH=/restconf/operations/zte-notifications:delete-subscription NETX_UME_NOTIFICATION_TOPIC=ALARM -# TLS verify for UME (default true). Set false only for lab self-signed certs. -# NETX_UME_VERIFY_TLS=true +# TLS verify for UME (default true). Lab self-signed UME must set false explicitly: +NETX_UME_VERIFY_TLS=false # Auth (lab defaults: admin/admin123 + data/auth/mcp_token) # NETX_AUTH_ENABLED=true # Leave NETX_AUTH_SECRET empty to auto-create data/auth/jwt_secret on first boot. diff --git a/netx_api/ume_client.py b/netx_api/ume_client.py index f526a0c..25c6d75 100644 --- a/netx_api/ume_client.py +++ b/netx_api/ume_client.py @@ -305,7 +305,17 @@ class UMEClient: self._lock_releaser() except Exception: pass - raise RuntimeError(f"ume_login_failed:{str(exc)[:240]}") from exc + detail = str(exc)[:240] + if self.verify_tls and ( + "CERTIFICATE_VERIFY_FAILED" in detail + or "certificate verify failed" in detail.lower() + or "SSLCertVerificationError" in type(exc).__name__ + ): + detail = ( + f"{detail} (hint: set NETX_UME_VERIFY_TLS=false for lab " + "self-signed UME, or pin a CA; restart API after change)" + ) + raise RuntimeError(f"ume_login_failed:{detail}") from exc token, ttl = self._extract_token_and_ttl(data) if not token: