-
Notifications
You must be signed in to change notification settings - Fork 1.3k
CPVM: use X509ExtendedTrustManager to skip hostname verification #5419
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CPVM: use X509ExtendedTrustManager to skip hostname verification #5419
Conversation
|
@blueorangutan package |
|
@weizhouapache a Jenkins job has been kicked to build packages. I'll keep you posted as I make progress. |
|
Packaging result: ✖️ el7 ✖️ el8 ✔️ debian ✔️ suse15. SL-JID 1175 |
|
Hi @coreymr can you please test with the following file in CPVM ? |
|
@blueorangutan package |
|
@weizhouapache a Jenkins job has been kicked to build packages. I'll keep you posted as I make progress. |
|
Packaging result: ✔️ el7 ✔️ el8 ✔️ debian. SL-JID 1177 |
|
@rhtyd @nvazquez Mike has confirmed it fixes his console issue on vmware 7. |
nvazquez
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
|
Thanks @weizhouapache, @rhtyd can this be included on 4.15.2? |
|
@blueorangutan package |
|
@nvazquez a Jenkins job has been kicked to build packages. I'll keep you posted as I make progress. |
|
Packaging result: ✔️ el7 ✔️ el8 ✔️ debian. SL-JID 1184 |
|
@blueorangutan test centos7 vmware-70u1 |
|
@nvazquez a Trillian-Jenkins test job (centos7 mgmt + vmware-70u1) has been kicked to run smoke tests |
|
@rhtyd @weizhouapache I think this is not a blocker, no need to include it on 4.15.2, do you agree? |
|
Trillian test result (tid-1992)
|
|
@blueorangutan test centos7 vmware-70u1 |
|
@nvazquez a Trillian-Jenkins test job (centos7 mgmt + vmware-70u1) has been kicked to run smoke tests |
|
Trillian test result (tid-2016)
|
|
cc @DaanHoogland @nvazquez @davidjumani - do we know what causes so many smoketest failures with Vmware7, can we fix them? |
yadvr
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM - did not test it, this would require some manual testing + 100% smoketests pass before merging.
|
@blueorangutan test centos7 vmware-65u2 |
|
@weizhouapache a Trillian-Jenkins test job (centos7 mgmt + vmware-65u2) has been kicked to run smoke tests |
|
@rhtyd @weizhouapache I've started a Vmware7 round of tests on the health check PR so we can compare if the failures are related to this PR or needs fixing |
|
@rhtyd @weizhouapache this fix has been tested by @coreymr, do we need additional tests? |
|
@nvazquez yes my concern is not specifically VMware7, but other regression testing hypervisors/version combinations (with/without SSL enabled?) - if it breaks anything? Or do you or @weizhouapache think that's not necessary? |
@rhtyd |
|
Thanks for confirming @weizhouapache |
|
(just curious why XenServer65? and what about Vmware 6.5/6.7?) |
@rhtyd sorry for typo. centos7 (ssl), ubuntu20 (non-ssl), vmware65 (non-ssl) and xenserver71 (non-ssl). |
|
@blueorangutan test centos7 vmware-70u1 keepEnv |
|
@weizhouapache a Trillian-Jenkins test job (centos7 mgmt + vmware-70u1) has been kicked to run smoke tests |
|
Trillian test result (tid-2068)
|
|
@rhtyd @nvazquez only the first ssh connection is ok, the next ssh attempts are refused. (it seems to be working in vmware65 environments) for default centos55 template, it works When I use centos55 for testing, tests passed. |
|
@NuxRo any input on this strange behaviour with macchinina and Vmware 7? |
sureshanaparti
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
code LGTM
@NuxRo |
|
@nvazquez @sureshanaparti |
|
@weizhouapache not before we have some agreement on the vmware failures (4.15 is fine, but I wonder if somebody will do a 4.15.3 as we'll soon have 4.16.0, 4.16.1 and 4.17.0 in the pipeline) |
|
ping @NuxRo @nvazquez @weizhouapache - kindly discuss and agree on whether this can be merged or some fixes in this PR or in trillian/lab env is needed. |
@rhtyd |
|
Agree with @weizhouapache, the failures are not related to the PR as the same were seen in the health checks PR, lets merge it and fix the issues for macchinina and Vmware 7 on a separate PR |
|
For those who have same issue with 4.15.2.0, please use the jar below in SSVM |
Description
This PR fixes #5413
Types of changes
Feature/Enhancement Scale or Bug Severity
Feature/Enhancement Scale
Bug Severity
Screenshots (if appropriate):
How Has This Been Tested?