mirror of
https://github.com/hansjone/netx.git
synced 2026-10-09 03:10:46 +08:00
Default UME TLS verify off for lab self-signed certs.
Restore ume_verify_tls=false so onsite UME login works without a .env override; production should set NETX_UME_VERIFY_TLS=true or pin a CA. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
0ebf137776
commit
6eeaa457b8
5 changed files with 6 additions and 16 deletions
|
|
@ -37,8 +37,8 @@ NETX_UME_ALARM_WS_ENABLED=true
|
||||||
NETX_UME_NOTIFICATION_ESTABLISH_PATH=/restconf/operations/zte-notifications:establish-subscription
|
NETX_UME_NOTIFICATION_ESTABLISH_PATH=/restconf/operations/zte-notifications:establish-subscription
|
||||||
NETX_UME_NOTIFICATION_DELETE_PATH=/restconf/operations/zte-notifications:delete-subscription
|
NETX_UME_NOTIFICATION_DELETE_PATH=/restconf/operations/zte-notifications:delete-subscription
|
||||||
NETX_UME_NOTIFICATION_TOPIC=ALARM
|
NETX_UME_NOTIFICATION_TOPIC=ALARM
|
||||||
# TLS verify for UME (default true). Lab self-signed UME must set false explicitly:
|
# TLS verify for UME (default false for lab self-signed). Production: set true or pin a CA.
|
||||||
NETX_UME_VERIFY_TLS=false
|
# NETX_UME_VERIFY_TLS=false
|
||||||
# Auth (lab defaults: admin/admin123 + data/auth/mcp_token)
|
# Auth (lab defaults: admin/admin123 + data/auth/mcp_token)
|
||||||
# NETX_AUTH_ENABLED=true
|
# NETX_AUTH_ENABLED=true
|
||||||
# Leave NETX_AUTH_SECRET empty to auto-create data/auth/jwt_secret on first boot.
|
# Leave NETX_AUTH_SECRET empty to auto-create data/auth/jwt_secret on first boot.
|
||||||
|
|
|
||||||
|
|
@ -3,7 +3,7 @@
|
||||||
## Security
|
## Security
|
||||||
- Prefer empty `NETX_AUTH_SECRET` so each install auto-writes `data/auth/jwt_secret` (do not commit that file). Set an explicit secret only for multi-node shared signing.
|
- Prefer empty `NETX_AUTH_SECRET` so each install auto-writes `data/auth/jwt_secret` (do not commit that file). Set an explicit secret only for multi-node shared signing.
|
||||||
- Leave `NETX_DOCS_ENABLED` unset/false so `/docs` and OpenAPI stay off (set `true` only in lab).
|
- Leave `NETX_DOCS_ENABLED` unset/false so `/docs` and OpenAPI stay off (set `true` only in lab).
|
||||||
- Keep `NETX_UME_VERIFY_TLS=true` (or pin a CA); avoid `false` on non-lab hosts.
|
- Set `NETX_UME_VERIFY_TLS=true` (or pin a CA) in production; default is `false` for lab self-signed UME.
|
||||||
- Binding `NETX_HOST` to a non-loopback address with lab defaults is refused unless `NETX_ALLOW_INSECURE_DEFAULTS=1`.
|
- Binding `NETX_HOST` to a non-loopback address with lab defaults is refused unless `NETX_ALLOW_INSECURE_DEFAULTS=1`.
|
||||||
- Prefer scoped API tokens (MCP default excludes `webcrt:session` / `sql:query`).
|
- Prefer scoped API tokens (MCP default excludes `webcrt:session` / `sql:query`).
|
||||||
- Keep `.env` and `oclaw/_local/system.env` out of Git (already ignored).
|
- Keep `.env` and `oclaw/_local/system.env` out of Git (already ignored).
|
||||||
|
|
|
||||||
|
|
@ -26,7 +26,7 @@ class Settings(BaseSettings):
|
||||||
ume_base_url: str = ""
|
ume_base_url: str = ""
|
||||||
ume_username: str = ""
|
ume_username: str = ""
|
||||||
ume_password: str = ""
|
ume_password: str = ""
|
||||||
ume_verify_tls: bool = True
|
ume_verify_tls: bool = False
|
||||||
ume_timeout_s: float = 20.0
|
ume_timeout_s: float = 20.0
|
||||||
ume_page_size: int = 1000
|
ume_page_size: int = 1000
|
||||||
ume_max_pages: int = 2000
|
ume_max_pages: int = 2000
|
||||||
|
|
|
||||||
|
|
@ -37,7 +37,7 @@ def assert_secure_defaults_or_exit() -> None:
|
||||||
pwd = str(settings.bootstrap_admin_password or "").strip()
|
pwd = str(settings.bootstrap_admin_password or "").strip()
|
||||||
if pwd in {"", "admin123"}:
|
if pwd in {"", "admin123"}:
|
||||||
problems.append("NETX_BOOTSTRAP_ADMIN_PASSWORD is still the lab default (admin123)")
|
problems.append("NETX_BOOTSTRAP_ADMIN_PASSWORD is still the lab default (admin123)")
|
||||||
if not bool(getattr(settings, "ume_verify_tls", True)):
|
if not bool(getattr(settings, "ume_verify_tls", False)):
|
||||||
problems.append("NETX_UME_VERIFY_TLS=false while binding on a non-loopback interface")
|
problems.append("NETX_UME_VERIFY_TLS=false while binding on a non-loopback interface")
|
||||||
if problems:
|
if problems:
|
||||||
for p in problems:
|
for p in problems:
|
||||||
|
|
|
||||||
|
|
@ -305,17 +305,7 @@ class UMEClient:
|
||||||
self._lock_releaser()
|
self._lock_releaser()
|
||||||
except Exception:
|
except Exception:
|
||||||
pass
|
pass
|
||||||
detail = str(exc)[:240]
|
raise RuntimeError(f"ume_login_failed:{str(exc)[:240]}") from exc
|
||||||
if self.verify_tls and (
|
|
||||||
"CERTIFICATE_VERIFY_FAILED" in detail
|
|
||||||
or "certificate verify failed" in detail.lower()
|
|
||||||
or "SSLCertVerificationError" in type(exc).__name__
|
|
||||||
):
|
|
||||||
detail = (
|
|
||||||
f"{detail} (hint: set NETX_UME_VERIFY_TLS=false for lab "
|
|
||||||
"self-signed UME, or pin a CA; restart API after change)"
|
|
||||||
)
|
|
||||||
raise RuntimeError(f"ume_login_failed:{detail}") from exc
|
|
||||||
|
|
||||||
token, ttl = self._extract_token_and_ttl(data)
|
token, ttl = self._extract_token_and_ttl(data)
|
||||||
if not token:
|
if not token:
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue