certs: conditional whining

This commit is contained in:
ed
2026-09-01 23:00:10 +02:00
parent 704af697c7
commit 80cf7bfdc0
3 changed files with 22 additions and 15 deletions
+6 -3
View File
@@ -39,6 +39,7 @@ from .__init__ import (
from .__version__ import CODENAME, S_BUILD_DT, S_VERSION
from .authsrv import expand_config_file, split_cfg_ln, upgrade_cfg_fmt
from .bos import bos
from .cert import NO_TLS
from .cfg import flagcats, onedash
from .mdns import DNS_VND
from .qrkode import VENDORED as QR_VND
@@ -100,11 +101,12 @@ if PY2:
range = xrange # type: ignore
try:
if os.environ.get("PRTY_NO_TLS"):
if NO_TLS:
raise Exception()
HAVE_SSL = True
import ssl
HAVE_SSL = True
except:
HAVE_SSL = False
@@ -2491,7 +2493,8 @@ def main(argv: Optional[list[str]] = None) -> None:
if al.ciphers:
configure_ssl_ciphers(al)
else:
warn("ssl module does not exist; cannot enable https")
if not al.http_only and not NO_TLS:
warn("ssl module does not exist; cannot enable https")
al.http_only = True
if PY2 and WINDOWS and al.e2d:
+5 -3
View File
@@ -8,6 +8,7 @@ import time
from .__init__ import ANYWIN
from .util import Netdev, atomic_move, load_resource, runcmd, wunlink
NO_TLS = bool(os.environ.get("PRTY_NO_TLS"))
HAVE_CFSSL = not os.environ.get("PRTY_NO_CFSSL")
if True: # pylint: disable=using-constant-test
@@ -70,8 +71,9 @@ def ensure_cert(log: "RootLogger", args) -> None:
with open(args.cert, "rb") as f:
active_cert = f.read()
if active_cert == cert_insec:
t = "using default TLS certificate; https will be insecure:\033[36m {}"
log("cert", t.format(args.cert), 3)
t = "using default TLS certificate; %s will be insecure:\033[36m %s"
t2 = "https" if not args.ftps else "ftps"
log("cert", t % (t2, args.cert), 3)
except:
pass
@@ -252,7 +254,7 @@ def _gen_srv(log: "RootLogger", args, netdevs: dict[str, Netdev]):
def gencert(log: "RootLogger", args, netdevs: dict[str, Netdev]):
global HAVE_CFSSL
if args.http_only:
if args.http_only and not args.ftps:
return
if args.no_crt or args.certkey or not HAVE_CFSSL:
+11 -9
View File
@@ -8,22 +8,24 @@ import socket
import threading # typechk
import time
try:
if os.environ.get("PRTY_NO_TLS"):
raise Exception()
HAVE_SSL = True
import ssl
except:
HAVE_SSL = False
from . import util as Util
from .__init__ import TYPE_CHECKING, EnvParams
from .authsrv import AuthSrv # typechk
from .cert import NO_TLS
from .httpcli import HttpCli
from .u2idx import U2idx
from .util import HMaccas, NetMap, min_ex, shut_socket
try:
if NO_TLS:
raise Exception()
import ssl
HAVE_SSL = True
except:
HAVE_SSL = False
if True: # pylint: disable=using-constant-test
from typing import Optional, Pattern, Union