From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 54CD11FF138 for ; Tue, 21 Jul 2026 13:58:33 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id BA757214AE; Tue, 21 Jul 2026 13:58:32 +0200 (CEST) From: Erik Fastermann To: pve-devel@lists.proxmox.com Subject: [RFC qemu-server 1/4] remote migrate: drop ineffective fingerprint auto-detection Date: Tue, 21 Jul 2026 13:58:24 +0200 Message-ID: <20260721115827.163442-2-e.fastermann@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260721115827.163442-1-e.fastermann@proxmox.com> References: <20260721115827.163442-1-e.fastermann@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 2 AWL -0.069 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) KAM_LAZY_DOMAIN_SECURITY 1 Sending domain does not have any anti-forgery methods RDNS_NONE 1.274 Delivered to internal network by a host with no rDNS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_NONE 0.001 SPF: sender does not publish an SPF Record Message-ID-Hash: LHFNFV7AGRH5O5CFSND7ICJKKDCFT3XQ X-Message-ID-Hash: LHFNFV7AGRH5O5CFSND7ICJKKDCFT3XQ X-MailFrom: efastermann@ruth.proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Erik Fastermann X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: When no fingerprint was supplied, the code fetched the remote node certificate and pinned its fingerprint for the migration tunnel. This has no functional effect and is removed. That fetch only succeeds for remotes trusted via the CA store, which is exactly the case where pinning is unnecessary: both the API client and the websocket tunnel fall back to CA verification on their own. For a self-signed remote the fetch itself fails verification, so no fingerprint is ever obtained. The only meaningful path, an explicitly supplied fingerprint (needed to verify self-signed remotes), is unchanged. Signed-off-by: Erik Fastermann --- src/PVE/API2/Qemu.pm | 16 ++-------------- 1 file changed, 2 insertions(+), 14 deletions(-) diff --git a/src/PVE/API2/Qemu.pm b/src/PVE/API2/Qemu.pm index 28cbb9b0..68f1800c 100644 --- a/src/PVE/API2/Qemu.pm +++ b/src/PVE/API2/Qemu.pm @@ -5739,26 +5739,14 @@ __PACKAGE__->register_method({ apitoken => $remote->{apitoken}, }; - my $fp; - if ($fp = $remote->{fingerprint}) { - $conn_args->{cached_fingerprints} = { uc($fp) => 1 }; + if ($remote->{fingerprint}) { + $conn_args->{cached_fingerprints} = { uc($remote->{fingerprint}) => 1 }; } print "Establishing API connection with remote at '$remote->{host}'\n"; my $api_client = PVE::APIClient::LWP->new(%$conn_args); - if (!defined($fp)) { - my $cert_info = $api_client->get("/nodes/localhost/certificates/info"); - foreach my $cert (@$cert_info) { - my $filename = $cert->{filename}; - next if $filename ne 'pveproxy-ssl.pem' && $filename ne 'pve-ssl.pem'; - $fp = $cert->{fingerprint} if !$fp || $filename eq 'pveproxy-ssl.pem'; - } - $conn_args->{cached_fingerprints} = { uc($fp) => 1 } - if defined($fp); - } - my $repl_conf = PVE::ReplicationConfig->new(); my $is_replicated = $repl_conf->check_for_existing_jobs($source_vmid, 1); die "cannot remote-migrate replicated VM\n" if $is_replicated; -- 2.47.3