diff options
author | Phil Dibowitz <phil@ipom.com> | 2015-01-20 09:46:57 -0800 |
---|---|---|
committer | Phil Dibowitz <phil@ipom.com> | 2015-01-20 09:46:57 -0800 |
commit | b622710cd1ee8af39bc3ff255e2394c0115abaac (patch) | |
tree | 12c53d5ad8a97d1e2e740ba5b30943ca70d7a75c /lib/chef | |
parent | b9e91171f6bd4ac55d62c6b9b72838fa89a1330e (diff) | |
parent | d29a38eb258c006bec566fac30f142aeae0c9e36 (diff) | |
download | chef-b622710cd1ee8af39bc3ff255e2394c0115abaac.tar.gz |
Merge pull request #2762 from jaymzh/sslwarn
Suppress SSL warnings if I know what I'm doing
Diffstat (limited to 'lib/chef')
-rw-r--r-- | lib/chef/client.rb | 33 |
1 files changed, 0 insertions, 33 deletions
diff --git a/lib/chef/client.rb b/lib/chef/client.rb index 77f63671d7..3d9678ea31 100644 --- a/lib/chef/client.rb +++ b/lib/chef/client.rb @@ -419,8 +419,6 @@ class Chef begin runlock.save_pid - check_ssl_config - request_id = Chef::RequestID.instance.request_id run_context = nil @events.run_start(Chef::VERSION) @@ -529,37 +527,6 @@ class Chef Chef::ReservedNames::Win32::Security.has_admin_privileges? end - def check_ssl_config - if Chef::Config[:ssl_verify_mode] == :verify_none and !Chef::Config[:verify_api_cert] - Chef::Log.warn(<<-WARN) - -* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * -SSL validation of HTTPS requests is disabled. HTTPS connections are still -encrypted, but chef is not able to detect forged replies or man in the middle -attacks. - -To fix this issue add an entry like this to your configuration file: - -``` - # Verify all HTTPS connections (recommended) - ssl_verify_mode :verify_peer - - # OR, Verify only connections to chef-server - verify_api_cert true -``` - -To check your SSL configuration, or troubleshoot errors, you can use the -`knife ssl check` command like so: - -``` - knife ssl check -c #{Chef::Config.config_file} -``` - -* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * -WARN - end - end - end end |