From f6f1a946cfd55c2d944811ffc37401cb68d3885d Mon Sep 17 00:00:00 2001 From: pramoh Date: Sat, 6 Feb 2021 04:27:43 +0000 Subject: [PATCH 1/2] add noTLS support --- dockers/docker-sonic-telemetry/telemetry.sh | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/dockers/docker-sonic-telemetry/telemetry.sh b/dockers/docker-sonic-telemetry/telemetry.sh index 0fd80fcbfcc8..3b523911f3d2 100755 --- a/dockers/docker-sonic-telemetry/telemetry.sh +++ b/dockers/docker-sonic-telemetry/telemetry.sh @@ -23,7 +23,7 @@ if [ -n "$CERTS" ]; then SERVER_CRT=$(echo $CERTS | jq -r '.server_crt') SERVER_KEY=$(echo $CERTS | jq -r '.server_key') if [ -z $SERVER_CRT ] || [ -z $SERVER_KEY ]; then - TELEMETRY_ARGS+=" --insecure" + TELEMETRY_ARGS+=" --noTLS" else TELEMETRY_ARGS+=" --server_crt $SERVER_CRT --server_key $SERVER_KEY " fi @@ -36,7 +36,7 @@ elif [ -n "$X509" ]; then SERVER_CRT=$(echo $X509 | jq -r '.server_crt') SERVER_KEY=$(echo $X509 | jq -r '.server_key') if [ -z $SERVER_CRT ] || [ -z $SERVER_KEY ]; then - TELEMETRY_ARGS+=" --insecure" + TELEMETRY_ARGS+=" --noTLS" else TELEMETRY_ARGS+=" --server_crt $SERVER_CRT --server_key $SERVER_KEY " fi @@ -46,13 +46,12 @@ elif [ -n "$X509" ]; then TELEMETRY_ARGS+=" --ca_crt $CA_CRT" fi else - TELEMETRY_ARGS+=" --insecure" + TELEMETRY_ARGS+=" --noTLS" fi # If no configuration entry exists for TELEMETRY, create one default port if [ -z "$GNMI" ]; then PORT=8080 - sonic-db-cli CONFIG_DB hset "TELEMETRY|gnmi" port $PORT else PORT=$(echo $GNMI | jq -r '.port') fi From 3ff41d9d24f11d602305256b67fe8202469e20e0 Mon Sep 17 00:00:00 2001 From: pramoh Date: Tue, 9 Feb 2021 04:10:47 +0000 Subject: [PATCH 2/2] revert to insecure --- dockers/docker-sonic-telemetry/telemetry.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/dockers/docker-sonic-telemetry/telemetry.sh b/dockers/docker-sonic-telemetry/telemetry.sh index 3b523911f3d2..1f92657e3b8f 100755 --- a/dockers/docker-sonic-telemetry/telemetry.sh +++ b/dockers/docker-sonic-telemetry/telemetry.sh @@ -23,7 +23,7 @@ if [ -n "$CERTS" ]; then SERVER_CRT=$(echo $CERTS | jq -r '.server_crt') SERVER_KEY=$(echo $CERTS | jq -r '.server_key') if [ -z $SERVER_CRT ] || [ -z $SERVER_KEY ]; then - TELEMETRY_ARGS+=" --noTLS" + TELEMETRY_ARGS+=" --insecure" else TELEMETRY_ARGS+=" --server_crt $SERVER_CRT --server_key $SERVER_KEY " fi @@ -36,7 +36,7 @@ elif [ -n "$X509" ]; then SERVER_CRT=$(echo $X509 | jq -r '.server_crt') SERVER_KEY=$(echo $X509 | jq -r '.server_key') if [ -z $SERVER_CRT ] || [ -z $SERVER_KEY ]; then - TELEMETRY_ARGS+=" --noTLS" + TELEMETRY_ARGS+=" --insecure" else TELEMETRY_ARGS+=" --server_crt $SERVER_CRT --server_key $SERVER_KEY " fi