From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 55D741FF0E6 for ; Fri, 07 Aug 2026 11:12:40 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 92D9F214F1; Fri, 07 Aug 2026 11:12:40 +0200 (CEST) From: Erik Fastermann To: pve-devel@lists.proxmox.com Subject: [PATCH qemu-server v2 1/5] remote migration: drop ineffective fingerprint auto-detection Date: Fri, 7 Aug 2026 11:12:23 +0200 Message-ID: <20260807091227.73614-2-e.fastermann@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260807091227.73614-1-e.fastermann@proxmox.com> References: <20260807091227.73614-1-e.fastermann@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 1 AWL -0.572 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) KAM_LAZY_DOMAIN_SECURITY 1 Sending domain does not have any anti-forgery methods RDNS_NONE 1.274 Delivered to internal network by a host with no rDNS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_NONE 0.001 SPF: sender does not publish an SPF Record Message-ID-Hash: CB6Z6KBCY3XRFDHEN3I2DZ5WBGYI4UQS X-Message-ID-Hash: CB6Z6KBCY3XRFDHEN3I2DZ5WBGYI4UQS X-MailFrom: efastermann@ruth.proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Erik Fastermann X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: When no fingerprint was supplied, the code fetched the remote node certificate and pinned its fingerprint for the migration tunnel. This has no functional effect and is removed. That fetch only succeeds for remotes trusted via the CA store, which is exactly the case where pinning is unnecessary: both the API client and the websocket tunnel fall back to CA verification on their own. For a self-signed remote the fetch itself fails verification, so no fingerprint is ever obtained. The only meaningful path, an explicitly supplied fingerprint (needed to verify self-signed remotes), is unchanged. Signed-off-by: Erik Fastermann --- See the discussion on the RFC for more details [0]. [0]: https://lore.proxmox.com/pve-devel/1785319378.5wn648ra0k.astroid@yuna.none/ src/PVE/API2/Qemu.pm | 16 ++-------------- 1 file changed, 2 insertions(+), 14 deletions(-) diff --git a/src/PVE/API2/Qemu.pm b/src/PVE/API2/Qemu.pm index 39c725d0..56c5f08c 100644 --- a/src/PVE/API2/Qemu.pm +++ b/src/PVE/API2/Qemu.pm @@ -5751,26 +5751,14 @@ __PACKAGE__->register_method({ apitoken => $remote->{apitoken}, }; - my $fp; - if ($fp = $remote->{fingerprint}) { - $conn_args->{cached_fingerprints} = { uc($fp) => 1 }; + if ($remote->{fingerprint}) { + $conn_args->{cached_fingerprints} = { uc($remote->{fingerprint}) => 1 }; } print "Establishing API connection with remote at '$remote->{host}'\n"; my $api_client = PVE::APIClient::LWP->new(%$conn_args); - if (!defined($fp)) { - my $cert_info = $api_client->get("/nodes/localhost/certificates/info"); - foreach my $cert (@$cert_info) { - my $filename = $cert->{filename}; - next if $filename ne 'pveproxy-ssl.pem' && $filename ne 'pve-ssl.pem'; - $fp = $cert->{fingerprint} if !$fp || $filename eq 'pveproxy-ssl.pem'; - } - $conn_args->{cached_fingerprints} = { uc($fp) => 1 } - if defined($fp); - } - my $repl_conf = PVE::ReplicationConfig->new(); my $is_replicated = $repl_conf->check_for_existing_jobs($source_vmid, 1); die "cannot remote-migrate replicated VM\n" if $is_replicated; -- 2.47.3