From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 58FBE1FF0E5 for ; Wed, 29 Jul 2026 11:59:35 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 2572621353; Wed, 29 Jul 2026 11:59:35 +0200 (CEST) Message-ID: Date: Wed, 29 Jul 2026 11:59:05 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [RFC qemu-server 1/4] remote migrate: drop ineffective fingerprint auto-detection From: Fiona Ebner To: Erik Fastermann , pve-devel@lists.proxmox.com References: <20260721115827.163442-1-e.fastermann@proxmox.com> <20260721115827.163442-2-e.fastermann@proxmox.com> Content-Language: en-US In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1785319106630 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.177 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_LOW -0.7 Sender listed at https://www.dnswl.org/, low trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: SD223F2HVM3P27L4TZDTMQA7ZL267B4F X-Message-ID-Hash: SD223F2HVM3P27L4TZDTMQA7ZL267B4F X-MailFrom: f.ebner@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Forgot to CC Fabian, doing it now :) Am 29.07.26 um 11:57 AM schrieb Fiona Ebner: > Am 21.07.26 um 1:58 PM schrieb Erik Fastermann: >> When no fingerprint was supplied, the code fetched the remote node >> certificate and pinned its fingerprint for the migration tunnel. This >> has no functional effect and is removed. >> >> That fetch only succeeds for remotes trusted via the CA store, which >> is exactly the case where pinning is unnecessary: both the API client >> and the websocket tunnel fall back to CA verification on their own. >> For a self-signed remote the fetch itself fails verification, so no >> fingerprint is ever obtained. > > The websocket tunnel checks the pinned fingerprint against the one that > was supplied, so with the current code any weird scenario where the > fingerprint queried from the certificates API endpoint does not match > the one gotten later by the websocket tunnel connection is caught. If > you remove the pinning, such scenarios won't be caught anymore. Not sure > how important that is though. > > @Fabian what do you think? > >> >> The only meaningful path, an explicitly supplied fingerprint (needed to >> verify self-signed remotes), is unchanged. >> >> Signed-off-by: Erik Fastermann >> --- >> src/PVE/API2/Qemu.pm | 16 ++-------------- >> 1 file changed, 2 insertions(+), 14 deletions(-) >> >> diff --git a/src/PVE/API2/Qemu.pm b/src/PVE/API2/Qemu.pm >> index 28cbb9b0..68f1800c 100644 >> --- a/src/PVE/API2/Qemu.pm >> +++ b/src/PVE/API2/Qemu.pm >> @@ -5739,26 +5739,14 @@ __PACKAGE__->register_method({ >> apitoken => $remote->{apitoken}, >> }; >> >> - my $fp; >> - if ($fp = $remote->{fingerprint}) { >> - $conn_args->{cached_fingerprints} = { uc($fp) => 1 }; >> + if ($remote->{fingerprint}) { >> + $conn_args->{cached_fingerprints} = { uc($remote->{fingerprint}) => 1 }; >> } >> >> print "Establishing API connection with remote at '$remote->{host}'\n"; >> >> my $api_client = PVE::APIClient::LWP->new(%$conn_args); >> >> - if (!defined($fp)) { >> - my $cert_info = $api_client->get("/nodes/localhost/certificates/info"); >> - foreach my $cert (@$cert_info) { >> - my $filename = $cert->{filename}; >> - next if $filename ne 'pveproxy-ssl.pem' && $filename ne 'pve-ssl.pem'; >> - $fp = $cert->{fingerprint} if !$fp || $filename eq 'pveproxy-ssl.pem'; >> - } >> - $conn_args->{cached_fingerprints} = { uc($fp) => 1 } >> - if defined($fp); >> - } >> - >> my $repl_conf = PVE::ReplicationConfig->new(); >> my $is_replicated = $repl_conf->check_for_existing_jobs($source_vmid, 1); >> die "cannot remote-migrate replicated VM\n" if $is_replicated; > > > > >