Page MenuHomeVyOS Platform

config-sync: CLI options to verify the secondary's TLS certificate (PKI CA reference + peer fingerprint)
Open, NormalPublic

Description

Follow-up to T8955 (vyos-1x #5249).

Background

T8955 changes python/vyos/http_api_client.py so it verifies TLS by default. src/op_mode/config_sync.py still passes verify_tls=False explicitly, so existing self-signed secondaries keep working. As a result, config-sync still does not verify the secondary's certificate. The API key and the full configuration therefore travel over an unauthenticated TLS channel.

In the review of vyos-1x#5249, dmbaturin pointed out that many deployments use self-signed certificates. Verification therefore needs to work against a pinned fingerprint, not only against a CA store.

Proposed CLI

Under service config-sync secondary:

  • ca-certificate <name>: verify the secondary against a CA from pki ca. This follows the existing PKI-reference pattern, e.g. OpenVPN/stunnel/IPsec x509 ca-certificate.
  • peer-fingerprint <sha256>: pin the secondary's certificate fingerprint. This follows the interfaces openvpn ... peer-fingerprint precedent and covers self-signed secondaries.
  • Neither set: keep the current behaviour (no verification). Consider a commit-time warning saying the channel is unauthenticated.

Scope

  • XML under interface-definitions/service_config-sync.xml.in, plus validation in the conf_mode script. Decide whether ca-certificate and peer-fingerprint may be set together or are mutually exclusive.
  • Client support in http_api_client.py. A CA reference maps to a CA bundle path via verify=<path>. Fingerprint pinning needs a custom transport adapter, for example urllib3's assert_fingerprint. Verify the exact mechanism against current requests/urllib3 docs before implementing.
  • config_sync.py: read the new options and pass them through.
  • Smoketest coverage for the CLI and validation.
  • Docs: vyos-documentation config-sync page.
  • Open question: whether the default should eventually change to "verify required", with a migration script. Not in the first iteration.

Details

Version
rolling
Issue type
Feature (new functionality)

Event Timeline

syncer triaged this task as Normal priority.
syncer created this object with visibility "Public (No Login Required)".
syncer created this object with edit policy "Custom Policy".