Skip to content

[patch] Move SSLError handling to python-devops/src/mas/devops/utils.py, simplify validateEntitlementKey in cli.py - #2599

Open
Jeel-Oza wants to merge 10 commits into
masterfrom
mascore-16263
Open

Jeel-Oza wants to merge 10 commits into
masterfrom
mascore-16263

Conversation

@Jeel-Oza

@Jeel-Oza Jeel-Oza commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

[patch] Move SSLError handling to python-devops/src/mas/devops/utils.py, simplify validateEntitlementKey in cli.py

Summary

Fixes entitlement key validation failing with an unhelpful error message when the CLI cannot reach cp.icr.io due to an SSL certificate verification error (e.g. corporate proxy or firewall performing TLS interception).

Previously, all failures — whether SSL errors or genuine authentication failures — were surfaced as the same generic error, leaving customers unable to determine whether their key was wrong or the network was blocking the connection.

Changes

python/src/mas/cli/cli.py

  • Added RequestsException import to catch unexpected non-SSL network errors re-raised from utils.py
  • Updated validateEntitlementKey() — now catches RequestsException (non-SSL network errors) and returns False; SSLError is handled in utils.py and arrives as None
  • promptForEntitlementKey() — SSL-specific warning messages and interactive menu retained (unchanged)

python/tests/unit/test_entitlement_key_validation.py

  • Updated test_validate_with_ssl_error — changed side_effect=SSLError to return_value=None to reflect that utils.py now absorbs SSLError internally and returns None
  • Updated test_validate_with_network_error and test_validate_with_timeout — changed to side_effect=ConnectionError/Timeout to reflect that utils.py re-raises these and cli.py catches them and returns False
  • Updated assertions accordingly

Testing

Reproduced both scenarios manually inside the MAS CLI container.

Case 1 — SSL error (corporate proxy / self-signed certificate)

# Generate a fake CA cert that Python will not trust for cp.icr.io
openssl req -x509 -newkey rsa:2048 -keyout /tmp/fake-ca.key \
  -out /tmp/fake-ca.crt -days 1 -nodes \
  -subj "/CN=FakeCA"

# Force requests to use the fake bundle
export REQUESTS_CA_BUNDLE=/tmp/fake-ca.crt

# Run the CLI and enter any entitlement key
mas install

Result: Warning: SSL certificate verification failed — could not reach cp.icr.io with explanation that the key may still be valid and options to try again / continue / quit

Screenshot 2026-09-25 at 6 02 19 PM Screenshot 2026-09-25 at 6 01 59 PM

Case 2 — Wrong entitlement key

# Unset the fake CA bundle so the network is reachable
unset REQUESTS_CA_BUNDLE

# Run the CLI and enter a deliberately wrong entitlement key
mas install

Result: Warning: IBM entitlement key validation failed with options to try again / continue / quit

Screenshot 2026-09-25 at 6 02 50 PM

Linked issue

Fixes MASCORE-16263
Closes #2519

@Jeel-Oza
Jeel-Oza requested a review from terc1997 September 18, 2026 18:34
@Jeel-Oza
Jeel-Oza requested a review from a team as a code owner September 18, 2026 18:34

@terc1997 terc1997 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR on python-devops will change the implementation in the CLI.

@Jeel-Oza
Jeel-Oza requested a review from terc1997 September 25, 2026 13:22

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Entitlement key validation failure

2 participants