open(): auth error hides why the earlier transports failed #2

Closed
opened 2026-09-25 06:37:59 +00:00 by christianmanivong · 0 comments
Owner

Failure signature

Polling a ProCurve switch (172.22.8.40) from netOrk fails with:

ConnectionException: Authentifizierung fehlgeschlagen (172.22.8.40): Authentication failed for 172.22.8.40: Login failed: 172.22.8.40

The switch therefore has no interfaces in netOrk.

What actually happens

open() tries REST API → SSH → SSH (legacy KEX) → Telnet in turn (procurve.py open()).
Login failed: <host> is netmiko's text from telnet_login (netmiko/base_connection.py), so the three earlier transports had already failed. Their reasons are dropped:

  • _try_api only logs "REST API not detected" / "connect failed" at warning/debug level
  • _try_ssh swallows timeouts and every non-auth exception at debug level and returns False

Only the last transport's error reaches the caller. The message says "wrong password", when the real cause may be that SSH is disabled or refused, and Telnet is merely the one transport left that answers.

Expected

The error names the transport that failed and the reasons for every transport tried before it, e.g.
Authentication failed for 172.22.8.40 via telnet: Login failed: 172.22.8.40 (earlier: api: not detected; ssh: Connection refused; ssh_legacy: Connection refused).
The same applies to the final "Cannot connect … Tried transports: …" error, which lists names but no reasons.

## Failure signature Polling a ProCurve switch (172.22.8.40) from netOrk fails with: ``` ConnectionException: Authentifizierung fehlgeschlagen (172.22.8.40): Authentication failed for 172.22.8.40: Login failed: 172.22.8.40 ``` The switch therefore has no interfaces in netOrk. ## What actually happens `open()` tries REST API → SSH → SSH (legacy KEX) → Telnet in turn (`procurve.py` `open()`). `Login failed: <host>` is netmiko's text from `telnet_login` (`netmiko/base_connection.py`), so the three earlier transports had already failed. Their reasons are dropped: - `_try_api` only logs "REST API not detected" / "connect failed" at warning/debug level - `_try_ssh` swallows timeouts and every non-auth exception at debug level and returns `False` Only the last transport's error reaches the caller. The message says "wrong password", when the real cause may be that SSH is disabled or refused, and Telnet is merely the one transport left that answers. ## Expected The error names the transport that failed and the reasons for every transport tried before it, e.g. `Authentication failed for 172.22.8.40 via telnet: Login failed: 172.22.8.40 (earlier: api: not detected; ssh: Connection refused; ssh_legacy: Connection refused)`. The same applies to the final "Cannot connect … Tried transports: …" error, which lists names but no reasons.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: NAPALM/napalm-hpe-aruba-procurve#2