From 6eeaa457b82b8cec8c318eb5526177481752af18 Mon Sep 17 00:00:00 2001 From: oliver Date: Thu, 6 Aug 2026 15:15:48 +0800 Subject: [PATCH] Default UME TLS verify off for lab self-signed certs. Restore ume_verify_tls=false so onsite UME login works without a .env override; production should set NETX_UME_VERIFY_TLS=true or pin a CA. Co-authored-by: Cursor --- .env.example | 4 ++-- PROD_MIN_CHECKLIST.md | 2 +- netx_api/config.py | 2 +- netx_api/security_bootstrap.py | 2 +- netx_api/ume_client.py | 12 +----------- 5 files changed, 6 insertions(+), 16 deletions(-) diff --git a/.env.example b/.env.example index c1012c9..6df2c13 100644 --- a/.env.example +++ b/.env.example @@ -37,8 +37,8 @@ NETX_UME_ALARM_WS_ENABLED=true NETX_UME_NOTIFICATION_ESTABLISH_PATH=/restconf/operations/zte-notifications:establish-subscription NETX_UME_NOTIFICATION_DELETE_PATH=/restconf/operations/zte-notifications:delete-subscription NETX_UME_NOTIFICATION_TOPIC=ALARM -# TLS verify for UME (default true). Lab self-signed UME must set false explicitly: -NETX_UME_VERIFY_TLS=false +# TLS verify for UME (default false for lab self-signed). Production: set true or pin a CA. +# NETX_UME_VERIFY_TLS=false # Auth (lab defaults: admin/admin123 + data/auth/mcp_token) # NETX_AUTH_ENABLED=true # Leave NETX_AUTH_SECRET empty to auto-create data/auth/jwt_secret on first boot. diff --git a/PROD_MIN_CHECKLIST.md b/PROD_MIN_CHECKLIST.md index 0140727..cd0aa2a 100644 --- a/PROD_MIN_CHECKLIST.md +++ b/PROD_MIN_CHECKLIST.md @@ -3,7 +3,7 @@ ## Security - Prefer empty `NETX_AUTH_SECRET` so each install auto-writes `data/auth/jwt_secret` (do not commit that file). Set an explicit secret only for multi-node shared signing. - Leave `NETX_DOCS_ENABLED` unset/false so `/docs` and OpenAPI stay off (set `true` only in lab). -- Keep `NETX_UME_VERIFY_TLS=true` (or pin a CA); avoid `false` on non-lab hosts. +- Set `NETX_UME_VERIFY_TLS=true` (or pin a CA) in production; default is `false` for lab self-signed UME. - Binding `NETX_HOST` to a non-loopback address with lab defaults is refused unless `NETX_ALLOW_INSECURE_DEFAULTS=1`. - Prefer scoped API tokens (MCP default excludes `webcrt:session` / `sql:query`). - Keep `.env` and `oclaw/_local/system.env` out of Git (already ignored). diff --git a/netx_api/config.py b/netx_api/config.py index cbd2d59..a7ba304 100644 --- a/netx_api/config.py +++ b/netx_api/config.py @@ -26,7 +26,7 @@ class Settings(BaseSettings): ume_base_url: str = "" ume_username: str = "" ume_password: str = "" - ume_verify_tls: bool = True + ume_verify_tls: bool = False ume_timeout_s: float = 20.0 ume_page_size: int = 1000 ume_max_pages: int = 2000 diff --git a/netx_api/security_bootstrap.py b/netx_api/security_bootstrap.py index 03c3c70..6052793 100644 --- a/netx_api/security_bootstrap.py +++ b/netx_api/security_bootstrap.py @@ -37,7 +37,7 @@ def assert_secure_defaults_or_exit() -> None: pwd = str(settings.bootstrap_admin_password or "").strip() if pwd in {"", "admin123"}: problems.append("NETX_BOOTSTRAP_ADMIN_PASSWORD is still the lab default (admin123)") - if not bool(getattr(settings, "ume_verify_tls", True)): + if not bool(getattr(settings, "ume_verify_tls", False)): problems.append("NETX_UME_VERIFY_TLS=false while binding on a non-loopback interface") if problems: for p in problems: diff --git a/netx_api/ume_client.py b/netx_api/ume_client.py index 25c6d75..f526a0c 100644 --- a/netx_api/ume_client.py +++ b/netx_api/ume_client.py @@ -305,17 +305,7 @@ class UMEClient: self._lock_releaser() except Exception: pass - detail = str(exc)[:240] - if self.verify_tls and ( - "CERTIFICATE_VERIFY_FAILED" in detail - or "certificate verify failed" in detail.lower() - or "SSLCertVerificationError" in type(exc).__name__ - ): - detail = ( - f"{detail} (hint: set NETX_UME_VERIFY_TLS=false for lab " - "self-signed UME, or pin a CA; restart API after change)" - ) - raise RuntimeError(f"ume_login_failed:{detail}") from exc + raise RuntimeError(f"ume_login_failed:{str(exc)[:240]}") from exc token, ttl = self._extract_token_and_ttl(data) if not token: