Update SocketService TLS config to be consistent with UrlService.
Simple consistency update, changes the `ssl` config item to `tls`, `ssl_key` to `tls_key_file`, and `ssl_cert` to `tls_cert_file`, as well as updating the internals of `SocketService` to use the term TLS instead of SSL, and propogating this change for the one plugin currently using this support.
Austin S. Hemmelgarn committed
May 3, 2018 at 08:39 UTC
1c9a6faa18046ee5a4afec53276c9cfcf866f745
3 files changed
+23
-23
conf.d/python.d/unbound.conf
+2
-2
@@ -67,8 +67,8 @@
67
# port: 8953 # WHat port to use (defaults to 8953)
68
# socket: /path/to/socket # A path to a UNIX socket to use instead
69
# # of a TCP connection
70
-# ssl_key: /path/to/key # The keyfile to use for authentication
71
-# ssl_cert: /path/to/key # The certificate to use for authentication
70
+# tls_key_file: /path/to/key # The key file to use for authentication
71
+# tls_cert_file: /path/to/key # The certificate to use for authentication
72
# extended: false @ Whether to collect extended stats or not
73
#
74
# In addition to the above, you can set the following to try and
python.d/python_modules/bases/FrameworkServices/SocketService.py
+18
-18
@@ -7,9 +7,9 @@ import socket
7
try:
8
import ssl
9
except ImportError:
10
- _SSL_SUPPORT = False
10
+ _TLS_SUPPORT = False
11
else:
12
- _SSL_SUPPORT = True
12
+ _TLS_SUPPORT = True
13
14
from bases.FrameworkServices.SimpleService import SimpleService
15
@@ -23,7 +23,7 @@ class SocketService(SimpleService):
23
self.unix_socket = None
24
self.dgram_socket = False
25
self.request = ''
26
- self.ssl = False
26
+ self.tls = False
27
self.cert = None
28
self.key = None
29
self.__socket_config = None
@@ -66,15 +66,15 @@ class SocketService(SimpleService):
66
self.__socket_config = None
67
return False
68
69
- if self.ssl:
69
+ if self.tls:
70
try:
71
- self.debug('Encapsulating socket with SSL')
71
+ self.debug('Encapsulating socket with TLS')
72
self._sock = ssl.wrap_socket(self._sock,
73
keyfile=self.key,
74
certfile=self.cert,
75
server_side=False,
76
cert_reqs=ssl.CERT_NONE)
77
- except (socket.error, ssl.SSLError) as error:
77
+ except (socket.error, ssl.TLSError) as error:
78
self.error('Failed to wrap socket.')
79
self._disconnect()
80
self.__socket_config = None
@@ -83,7 +83,7 @@ class SocketService(SimpleService):
83
try:
84
self.debug('connecting socket to "{address}", port {port}'.format(address=sa[0], port=sa[1]))
85
self._sock.connect(sa)
86
- except (socket.error, ssl.SSLError) as error:
86
+ except (socket.error, ssl.TLSError) as error:
87
self.error('Failed to connect to "{address}", port {port}, error: {error}'.format(address=sa[0],
88
port=sa[1],
89
error=error))
@@ -273,26 +273,26 @@ class SocketService(SimpleService):
273
except (KeyError, TypeError):
274
self.debug('No port specified. Using: "{0}"'.format(self.port))
275
276
- self.ssl = bool(self.configuration.get('ssl', self.ssl))
277
- if self.ssl and not _SSL_SUPPORT:
278
- self.warning('SSL requested but not SSL module found, disabling SSL support.')
279
- self.ssl = False
280
- if _SSL_SUPPORT and not self.ssl:
281
- self.debug('No SSL preference specified, not using SSL.')
276
+ self.tls = bool(self.configuration.get('tls', self.tls))
277
+ if self.tls and not _TLS_SUPPORT:
278
+ self.warning('TLS requested but no TLS module found, disabling TLS support.')
279
+ self.tls = False
280
+ if _TLS_SUPPORT and not self.tls:
281
+ self.debug('No TLS preference specified, not using TLS.')
282
283
- if self.ssl and _SSL_SUPPORT:
284
- self.key = self.configuration.get('ssl_key')
285
- self.cert = self.configuration.get('ssl_cert')
283
+ if self.tls and _TLS_SUPPORT:
284
+ self.key = self.configuration.get('tls_key_file')
285
+ self.cert = self.configuration.get('tls_cert_file')
286
if not self.cert:
287
# If there's not a valid certificate, clear the key too.
288
- self.debug('No valid SSL client certificate configuration found.')
288
+ self.debug('No valid TLS client certificate configuration found.')
289
self.key = None
290
self.cert = None
291
elif not self.key:
292
# If a key isn't listed, the config may still be
293
# valid, because there may be a key attached to the
294
# certificate.
295
- self.notice('No SSL client key specified, assuming it\'s attached to the certificate.')
295
+ self.notice('No TLS client key specified, assuming it\'s attached to the certificate.')
296
self.key = None
297
298
try:
python.d/unbound.chart.py
+3
-3
@@ -89,10 +89,10 @@ STAT_MAP = {
89
90
class Service(SocketService):
91
def __init__(self, configuration=None, name=None):
92
- # The unbound control protocol is always SSL encapsulated
93
- # unless it's used over a UNIX socket, so enable SSL _before_
92
+ # The unbound control protocol is always TLS encapsulated
93
+ # unless it's used over a UNIX socket, so enable TLS _before_
94
# doing the normal SocketService initialization.
95
- configuration['ssl'] = True
95
+ configuration['tls'] = True
96
self.port = 8935
97
SocketService.__init__(self, configuration, name)
98
self.ext = self.configuration.get('extended', None)