sassoftware / sassoftware/python-swat
Connection issue - accessing CAS in containerized Viya 4 environment from local Python client.
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 159
- Forks
- 65
- PR merge metrics
- No merged PRs in 30d
Description
My Python client is a local Jupyter notebook application running on my laptop. On my server, I have published both the HTTP and Binary CAS Node ports and also exposed them as Load Balancers, providing external IPs.
As a first check - I first used swat to access CAS from a Python client on the server - viz. through SAS Studio. Connections to https and bin ports are both successful.
There are two different error messages I get - both are SSL certificate related. The first one is when I connect with the below format ( is the alias for my ingress)
Situation 1 :
os.environ['CAS_CLIENT_SSL_CA_LIST']="trustedcerts.pem"
s = swat.CAS(hostname="<host>/sas-cas-server-default-http", port=443, protocol="https",
username="user",password=getpass.getpass("Enter password"))
Message (error portion):
SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:997)
Variants - tried with -bin (cas protocol) and with -client, port=443 and protocol=https
Next, I tried providing a hostname directly, and got the following error (which is a little funny, given that the hostname is actually part of the list of hosts.)
CertificateError: hostname '**10.A.B.C**' doesn't match either of '10.A.B.A', '**10.A.B.C**', 'controller', 'controller.sas-cas-server-default', '......'
I have verified my certificate and it is obtained from the cluster directly in per format.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the swat.CAS connection setup described for the local Jupyter client, including CAS_CLIENT_SSL_CA_LIST, trustedcerts.pem, the ingress alias, and the published HTTP and binary ports. Reproduce both SSL errors and compare the certificate and hostname presented through the ingress or load balancer with the hostname supplied to swat.CAS; done means the connection path and required configuration are identified.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- networking, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100