Follow-up to T8955 (vyos-1x #5249).
Background
T8955 changes python/vyos/http_api_client.py so it verifies TLS by default. src/op_mode/config_sync.py still passes verify_tls=False explicitly, so existing self-signed secondaries keep working. As a result, config-sync still does not verify the secondary's certificate. The API key and the full configuration therefore travel over an unauthenticated TLS channel.
In the review of vyos-1x#5249, dmbaturin pointed out that many deployments use self-signed certificates. Verification therefore needs to work against a pinned fingerprint, not only against a CA store.
Proposed CLI
Under service config-sync secondary:
- ca-certificate <name>: verify the secondary against a CA from pki ca. This follows the existing PKI-reference pattern, e.g. OpenVPN/stunnel/IPsec x509 ca-certificate.
- peer-fingerprint <sha256>: pin the secondary's certificate fingerprint. This follows the interfaces openvpn ... peer-fingerprint precedent and covers self-signed secondaries.
- Neither set: keep the current behaviour (no verification). Consider a commit-time warning saying the channel is unauthenticated.
Scope
- XML under interface-definitions/service_config-sync.xml.in, plus validation in the conf_mode script. Decide whether ca-certificate and peer-fingerprint may be set together or are mutually exclusive.
- Client support in http_api_client.py. A CA reference maps to a CA bundle path via verify=<path>. Fingerprint pinning needs a custom transport adapter, for example urllib3's assert_fingerprint. Verify the exact mechanism against current requests/urllib3 docs before implementing.
- config_sync.py: read the new options and pass them through.
- Smoketest coverage for the CLI and validation.
- Docs: vyos-documentation config-sync page.
- Open question: whether the default should eventually change to "verify required", with a migration script. Not in the first iteration.