From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 8DDD41FF0E5 for ; Wed, 29 Jul 2026 11:57:49 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 608B82143A; Wed, 29 Jul 2026 11:57:49 +0200 (CEST) Message-ID: Date: Wed, 29 Jul 2026 11:56:46 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [RFC qemu-server 1/4] remote migrate: drop ineffective fingerprint auto-detection To: Erik Fastermann , pve-devel@lists.proxmox.com References: <20260721115827.163442-1-e.fastermann@proxmox.com> <20260721115827.163442-2-e.fastermann@proxmox.com> Content-Language: en-US From: Fiona Ebner In-Reply-To: <20260721115827.163442-2-e.fastermann@proxmox.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1785318967465 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.179 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_LOW -0.7 Sender listed at https://www.dnswl.org/, low trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: EBSABYHPBSUU7ILCUMWJWHJS5VL3L7U7 X-Message-ID-Hash: EBSABYHPBSUU7ILCUMWJWHJS5VL3L7U7 X-MailFrom: f.ebner@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Am 21.07.26 um 1:58 PM schrieb Erik Fastermann: > When no fingerprint was supplied, the code fetched the remote node > certificate and pinned its fingerprint for the migration tunnel. This > has no functional effect and is removed. > > That fetch only succeeds for remotes trusted via the CA store, which > is exactly the case where pinning is unnecessary: both the API client > and the websocket tunnel fall back to CA verification on their own. > For a self-signed remote the fetch itself fails verification, so no > fingerprint is ever obtained. The websocket tunnel checks the pinned fingerprint against the one that was supplied, so with the current code any weird scenario where the fingerprint queried from the certificates API endpoint does not match the one gotten later by the websocket tunnel connection is caught. If you remove the pinning, such scenarios won't be caught anymore. Not sure how important that is though. @Fabian what do you think? > > The only meaningful path, an explicitly supplied fingerprint (needed to > verify self-signed remotes), is unchanged. > > Signed-off-by: Erik Fastermann > --- > src/PVE/API2/Qemu.pm | 16 ++-------------- > 1 file changed, 2 insertions(+), 14 deletions(-) > > diff --git a/src/PVE/API2/Qemu.pm b/src/PVE/API2/Qemu.pm > index 28cbb9b0..68f1800c 100644 > --- a/src/PVE/API2/Qemu.pm > +++ b/src/PVE/API2/Qemu.pm > @@ -5739,26 +5739,14 @@ __PACKAGE__->register_method({ > apitoken => $remote->{apitoken}, > }; > > - my $fp; > - if ($fp = $remote->{fingerprint}) { > - $conn_args->{cached_fingerprints} = { uc($fp) => 1 }; > + if ($remote->{fingerprint}) { > + $conn_args->{cached_fingerprints} = { uc($remote->{fingerprint}) => 1 }; > } > > print "Establishing API connection with remote at '$remote->{host}'\n"; > > my $api_client = PVE::APIClient::LWP->new(%$conn_args); > > - if (!defined($fp)) { > - my $cert_info = $api_client->get("/nodes/localhost/certificates/info"); > - foreach my $cert (@$cert_info) { > - my $filename = $cert->{filename}; > - next if $filename ne 'pveproxy-ssl.pem' && $filename ne 'pve-ssl.pem'; > - $fp = $cert->{fingerprint} if !$fp || $filename eq 'pveproxy-ssl.pem'; > - } > - $conn_args->{cached_fingerprints} = { uc($fp) => 1 } > - if defined($fp); > - } > - > my $repl_conf = PVE::ReplicationConfig->new(); > my $is_replicated = $repl_conf->check_for_existing_jobs($source_vmid, 1); > die "cannot remote-migrate replicated VM\n" if $is_replicated;