Bug 1677765
| Summary: | subscription-manager commands fail when configured to use an ssl proxy server | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | John Sefler <jsefler> |
| Component: | subscription-manager | Assignee: | Jiri Hnidek <jhnidek> |
| Status: | CLOSED WONTFIX | QA Contact: | Red Hat subscription-manager QE Team <rhsm-qe> |
| Severity: | medium | Docs Contact: | |
| Priority: | low | ||
| Version: | 8.0 | CC: | cdonnell, csnyder, jhnidek, khowell, redakkan, rjerrido |
| Target Milestone: | rc | Keywords: | Reopened, Triaged |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-02-01 07:32:49 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1673062 | ||
|
Description
John Sefler
2019-02-15 20:03:58 UTC
Testing: I ruled out networking issues between my RHEL 8 RC1 host and the lab by utilizing a new host with a ncat listener that is hosted on the same hypervisor as the RHEL 8 host. (Difference between auto-services location for squid connection.) RHEL 8 RC1 Client: [root@unused rhsm]# rpm -q subscription-manager subscription-manager-1.23.8-33.el8.x86_64 [root@unused rhsm]# subscription-manager config | grep proxy no_proxy = [] proxy_hostname = 10.12.208.90 proxy_password = redhat proxy_port = 4433 proxy_scheme = https proxy_user = redhat [root@unused rhsm]# subscription-manager register --serverurl=subscription.rhsm.stage.redhat.com:443/subscription --username=stage_auto_testuser --auto-attach <hangs waiting for response from ncat> Unable to reach the server at subscription.rhsm.stage.redhat.com:443/subscription ===================================================== Fedora 28 Listen Server: [root@qedocs ~]# ncat -k -l 4433 CONNECT subscription.rhsm.stage.redhat.com:443 HTTP/1.0 <<<------------------ Not HTTPS... User-Agent: RHSM/1.0 (cmd=subscription-manager) Host: subscription.rhsm.stage.redhat.com:443 Proxy-Authorization: Basic cmVkaGF0OnJlZGhhdA== no <me killing connection> ===================================================== The same results from the connection to ncat listener with 'https_proxy' set on the RHEL 8 Client. It seems that the proxy_scheme is not having an effect on the connection type or something fundamental about RHEL 8 has changed that is not allowing us to create an https based connection via python. Closed after discussion with Chris. I looked into this with the assistance of cdonnell, and we determined that although support is limited to newer versions of specific programs, curl at least supports the configuration where the proxy server uses TLS for the initial connection and the proxied resource is TLS as well. Specifically, HTTP CONNECT proxy where the proxy connection is through TLS. Unfortunately, this scenario is not well supported within Python itself (e.g. see https://bugs.python.org/issue29394). `http.client` assumes that the proxy connection is plain HTTP. I did a bit of POC-work and determined that it is *possible* to work-around by overriding the initial proxy connection within http.client to use an SSL-wrapped socket. However, there is added complexity as communication with the proxied server also needs TLS, and so it's necessary to use the openssl bio interfaces with `wrap_bio` (trying to `wrap_socket` an already wrapped socket doesn't work, as the same socket is then referenced by two different SSL contexts -> bad time). In the POC, I worked around by emulating a socket (including the `makefile` function) with `ssl.SSLObject` (backed by `wrap_bio`); see https://github.com/candlepin/subscription-manager/tree/khowell/ssl_proxy_support_poc Another possible option would be to use pycurl, as curl seems to have implemented this in https://github.com/curl/curl/commit/cb4e2be7c6d42ca0780f8e0a747cecf9ba45f151 , but this has some additional downstream complexities involving moving pycurl from AppStream to BaseOS, and adding another dependency to subscription-manager. After evaluating this issue, there are no plans to address it further or fix it in an upcoming release. Therefore, it is being closed. If plans change such that this issue will be fixed in an upcoming release, then the bug can be reopened. |