UrlService: allow to skip tls_verify for http scheme (#7223)
* allow ssl_verify option for http scheme
Ilya Mashchenko committed
Oct 31, 2019 at 10:05 UTC
f625fa0e88a4b75a0a4ac404118dcccfb6477e88
1 file changed
+18
-3
collectors/python.d.plugin/python_modules/bases/FrameworkServices/UrlService.py
+18
-3
@@ -15,7 +15,6 @@ try:
15
except AttributeError:
16
pass
17
18
-
18
# https://github.com/urllib3/urllib3/blob/master/CHANGES.rst#19-2014-07-04
19
# New retry logic and urllib3.util.retry.Retry configuration object. (Issue https://github.com/urllib3/urllib3/pull/326)
20
URLLIB3_MIN_REQUIRED_VERSION = '1.9'
@@ -103,9 +102,12 @@ class UrlService(SimpleService):
102
params['ca_certs'] = tls_ca_file
103
try:
104
url = header_kw.get('url') or self.url
106
- if url.startswith('https') and not self.tls_verify and not tls_ca_file:
105
+ is_https = url.startswith('https')
106
+ if skip_tls_verify(is_https, self.tls_verify, tls_ca_file):
107
params['ca_certs'] = None
108
- return manager(assert_hostname=False, cert_reqs='CERT_NONE', **params)
108
+ params['cert_reqs'] = 'CERT_NONE'
109
+ if is_https:
110
+ params['assert_hostname'] = False
111
return manager(**params)
112
except (urllib3.exceptions.ProxySchemeUnknown, TypeError) as error:
113
self.error('build_manager() error:', str(error))
@@ -175,3 +177,16 @@ class UrlService(SimpleService):
177
return True
178
self.error('_get_data() returned no data or type is not <dict>')
179
return False
180
+
181
+
182
+def skip_tls_verify(is_https, tls_verify, tls_ca_file):
183
+ # default 'tls_verify' value is None
184
+ # logic is:
185
+ # - never skip if there is 'tls_ca_file' file
186
+ # - skip by default for https
187
+ # - do not skip by default for http
188
+ if tls_ca_file:
189
+ return False
190
+ if is_https and not tls_verify:
191
+ return True
192
+ return tls_verify is False