summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorBenjamin Peterson <benjamin@python.org>2016-02-18 06:13:19 (GMT)
committerBenjamin Peterson <benjamin@python.org>2016-02-18 06:13:19 (GMT)
commitb2e3946d76e4a7a383187d2643ef51649ea4a243 (patch)
tree66e1c8ce49e67d584d5a8d7e90a2a48d66c208d6
parent1c2a7b59390911994694ba027c9579747d592f1b (diff)
downloadcpython-b2e3946d76e4a7a383187d2643ef51649ea4a243.zip
cpython-b2e3946d76e4a7a383187d2643ef51649ea4a243.tar.gz
cpython-b2e3946d76e4a7a383187d2643ef51649ea4a243.tar.bz2
open the cert store readonly
Patch from Chi Hsuan Yen.
-rw-r--r--Misc/NEWS2
-rw-r--r--Modules/_ssl.c8
2 files changed, 8 insertions, 2 deletions
diff --git a/Misc/NEWS b/Misc/NEWS
index b548090..7635529 100644
--- a/Misc/NEWS
+++ b/Misc/NEWS
@@ -50,6 +50,8 @@ Core and Builtins
Library
-------
+- Issue #25939: On Windows open the cert store readonly in ssl.enum_certificates.
+
- Issue #24303: Fix random EEXIST upon multiprocessing semaphores creation with
Linux PID namespaces enabled.
diff --git a/Modules/_ssl.c b/Modules/_ssl.c
index 9116d9f..8f34f95 100644
--- a/Modules/_ssl.c
+++ b/Modules/_ssl.c
@@ -3653,7 +3653,9 @@ PySSL_enum_certificates(PyObject *self, PyObject *args, PyObject *kwds)
if (result == NULL) {
return NULL;
}
- hStore = CertOpenSystemStore((HCRYPTPROV)NULL, store_name);
+ hStore = CertOpenStore(CERT_STORE_PROV_SYSTEM_A, 0, (HCRYPTPROV)NULL,
+ CERT_STORE_READONLY_FLAG | CERT_SYSTEM_STORE_LOCAL_MACHINE,
+ store_name);
if (hStore == NULL) {
Py_DECREF(result);
return PyErr_SetFromWindowsErr(GetLastError());
@@ -3741,7 +3743,9 @@ PySSL_enum_crls(PyObject *self, PyObject *args, PyObject *kwds)
if (result == NULL) {
return NULL;
}
- hStore = CertOpenSystemStore((HCRYPTPROV)NULL, store_name);
+ hStore = CertOpenStore(CERT_STORE_PROV_SYSTEM_A, 0, (HCRYPTPROV)NULL,
+ CERT_STORE_READONLY_FLAG | CERT_SYSTEM_STORE_LOCAL_MACHINE,
+ store_name);
if (hStore == NULL) {
Py_DECREF(result);
return PyErr_SetFromWindowsErr(GetLastError());