2
0
mirror of https://github.com/xcat2/xcat-core.git synced 2025-07-24 05:11:12 +00:00

issue 1171: set SSL_verifycn_scheme => none for IO::Socket::SSL->new

This commit is contained in:
wangxiaopeng
2016-06-22 10:04:04 -04:00
parent 0e44282fd5
commit ca7c9ad69a
9 changed files with 18 additions and 6 deletions

View File

@@ -249,6 +249,7 @@ if (ref($request) eq 'HASH') { # the request is an array, not pure XML
SSL_cert_file => $certfile,
SSL_ca_file => $cafile,
SSL_verify_mode => SSL_VERIFY_PEER,
SSL_verifycn_scheme => "none",
SSL_use_cert => 1,
Timeout => 0,
%sslargs,

View File

@@ -242,7 +242,8 @@ sub expandnoderange {
SSL_cert_file=>$homedir."/.xcat/client-cred.pem",
SSL_ca_file => $homedir."/.xcat/ca.pem",
SSL_use_cert => 1,
SSL_verify_mode => 1,
SSL_verify_mode => SSL_VERIFY_PEER,
SSL_verifycn_scheme => "none",
%sslargs,
);
die "Connection failure: $!\n" unless ($client);
@@ -297,7 +298,8 @@ sub getipmiattrs {
SSL_cert_file=>$homedir."/.xcat/client-cred.pem",
SSL_ca_file => $homedir."/.xcat/ca.pem",
SSL_use_cert => 1,
SSL_verify_mode => 1,
SSL_verify_mode => SSL_VERIFY_PEER,
SSL_verifycn_scheme => "none",
%sslargs,
);
die "Connection failure: $!\n" unless ($client);

View File

@@ -72,7 +72,8 @@ else { # the normal case of the user running the cmd - expand the noderange us
SSL_cert_file=> xCAT::Utils->getHomeDir()."/.xcat/client-cred.pem",
SSL_ca_file => xCAT::Utils->getHomeDir()."/.xcat/ca.pem",
SSL_use_cert => 1,
SSL_verify_mode => 1,
SSL_verify_mode => SSL_VERIFY_PEER,
SSL_verifycn_scheme => "none",
%sslargs,
);
die "Connection failure: $!\n" unless ($client);

View File

@@ -90,6 +90,7 @@ my $client = IO::Socket::SSL->new(
SSL_use_cert => 1,
%sslargs,
SSL_verify_mode => SSL_VERIFY_PEER,
SSL_verifycn_scheme => "none",
);
die "Connection failure: $!\n" unless ($client);
my %cmdref = (command => 'noderange', noderange => $noderange);

View File

@@ -74,7 +74,8 @@ my $client = IO::Socket::SSL->new(
SSL_cert_file=>$homedir."/.xcat/client-cred.pem",
SSL_ca_file => $homedir."/.xcat/ca.pem",
SSL_use_cert => 1,
SSL_verify_mode => 1,
SSL_verify_mode => SSL_VERIFY_PEER,
SSL_verifycn_scheme => "none",
%sslargs,
);
die "Connection failure: $!\n" unless ($client);

View File

@@ -71,7 +71,8 @@ my $client = IO::Socket::SSL->new(
SSL_cert_file=>$homedir."/.xcat/client-cred.pem",
SSL_ca_file => $homedir."/.xcat/ca.pem",
SSL_use_cert => 1,
SSL_verify_mode => 1,
SSL_verify_mode => SSL_VERIFY_PEER,
SSL_verifycn_scheme => "none",
%sslargs,
);
die "Connection failure: $!\n" unless ($client);

View File

@@ -71,7 +71,8 @@ else {
SSL_cert_file=>$homedir."/.xcat/client-cred.pem",
SSL_ca_file => $homedir."/.xcat/ca.pem",
SSL_use_cert => 1,
SSL_verify_mode => 1,
SSL_verify_mode => SSL_VERIFY_PEER,
SSL_verifycn_scheme => "none",
%sslargs,
);
die "Connection failure: $!\n" unless ($client);

View File

@@ -2477,6 +2477,8 @@ sub sendRequest {
SSL_key_file => $keyfile,
SSL_cert_file => $certfile,
SSL_ca_file => $cafile,
SSL_verify_mode => SSL_VERIFY_PEER,
SSL_verifycn_scheme => "none",
SSL_use_cert => 1,
Timeout => 15,);
}

View File

@@ -2991,6 +2991,8 @@ sub sendRequest {
SSL_key_file => $keyfile,
SSL_cert_file => $certfile,
SSL_ca_file => $cafile,
SSL_verify_mode => SSL_VERIFY_PEER,
SSL_verifycn_scheme => "none",
SSL_use_cert => 1,
Timeout => 15,);
}