Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| | | * | Issue #18709: Fix CVE-2013-4238. The SSL module now handles NULL bytes | Georg Brandl | 2014-09-30 | 1 | -0/+29 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | inside subjectAltName correctly. Formerly the module has used OpenSSL's GENERAL_NAME_print() function to get the string represention of ASN.1 strings for ``rfc822Name`` (email), ``dNSName`` (DNS) and ``uniformResourceIdentifier`` (URI). | |||||
| | * | | merge 3.2 (#20896) | Benjamin Peterson | 2014-03-12 | 1 | -3/+8 | |
| | |\ \ | | | |/ | ||||||
| | | * | use ssl.PROTOCOL_SSLv23 for maximum compatibility (closes #20896) | Benjamin Peterson | 2014-03-12 | 1 | -3/+8 | |
| | | | | ||||||
| | | * | Issue #17980: Fix possible abuse of ssl.match_hostname() for denial of ↵ | Antoine Pitrou | 2013-05-18 | 1 | -0/+11 | |
| | | | | | | | | | | | | | | | | service using certificates with many wildcards (CVE-2013-2099). | |||||
* | | | | merge 3.4 (#25530) | Benjamin Peterson | 2015-11-12 | 1 | -9/+9 | |
|\ \ \ \ | |/ / / | ||||||
| * | | | always set OP_NO_SSLv3 by default (closes #25530) | Benjamin Peterson | 2015-11-12 | 1 | -9/+9 | |
| | | | | ||||||
* | | | | Issue #24210: Silence more PendingDeprecationWarning warnings in tests. | Berker Peksag | 2015-05-16 | 1 | -7/+15 | |
| | | | | ||||||
* | | | | merge 3.4 (#23844) | Benjamin Peterson | 2015-04-02 | 1 | -1/+1 | |
|\ \ \ \ | |/ / / | ||||||
| * | | | replace 512 bit dh key with a 2014 bit one (closes #23844) | Benjamin Peterson | 2015-04-02 | 1 | -1/+1 | |
| | | | | | | | | | | | | | | | | Patch by Cédric Krier. | |||||
* | | | | Issue #23001: Few functions in modules mmap, ossaudiodev, socket, ssl, and | Serhiy Storchaka | 2015-03-20 | 1 | -0/+2 | |
| | | | | | | | | | | | | | | | | | | | | codecs, that accepted only read-only bytes-like object now accept writable bytes-like object too. | |||||
* | | | | Issue #20617: Remove unused import in test_ssl. | Berker Peksag | 2015-03-12 | 1 | -1/+0 | |
|\ \ \ \ | |/ / / | | | | | | | | | Patch by Mark Lawrence. | |||||
| * | | | Issue #20617: Remove unused import in test_ssl. | Berker Peksag | 2015-03-12 | 1 | -1/+0 | |
| | | | | | | | | | | | | | | | | Patch by Mark Lawrence. | |||||
* | | | | merge 3.4 | Benjamin Peterson | 2015-03-05 | 1 | -1/+2 | |
|\ \ \ \ | |/ / / | ||||||
| * | | | adjust test_crl_check for trusted first being default | Benjamin Peterson | 2015-03-05 | 1 | -1/+2 | |
| | | | | ||||||
* | | | | merge 3.4 | Benjamin Peterson | 2015-03-05 | 1 | -2/+3 | |
|\ \ \ \ | |/ / / | ||||||
| * | | | expose X509_V_FLAG_TRUSTED_FIRST | Benjamin Peterson | 2015-03-05 | 1 | -2/+3 | |
| | | | | ||||||
* | | | | Issue #23239: ssl.match_hostname() now supports matching of IP addresses. | Antoine Pitrou | 2015-02-15 | 1 | -0/+24 | |
| | | | | ||||||
* | | | | Issue #23345: merge from 3.4 | Ned Deily | 2015-02-05 | 1 | -1/+1 | |
|\ \ \ \ | |/ / / | ||||||
| * | | | Issue #23345: Prevent test_ssl failures with large OpenSSL patch level | Ned Deily | 2015-02-05 | 1 | -1/+1 | |
| | | | | | | | | | | | | | | | | values (like 0.9.8zc). | |||||
| * | | | Issue #21356: Make ssl.RAND_egd() optional to support LibreSSL. The | Victor Stinner | 2015-01-06 | 1 | -2/+3 | |
| | | | | | | | | | | | | | | | | | | | | availability of the function is checked during the compilation. Patch written by Bernard Spil. | |||||
| * | | | Issue #22935: Fix test_ssl when the SSLv3 protocol is not supported | Victor Stinner | 2014-12-12 | 1 | -1/+2 | |
| | | | | ||||||
* | | | | prefer server alpn ordering over the client's | Benjamin Peterson | 2015-01-23 | 1 | -2/+2 | |
| | | | | ||||||
* | | | | add support for ALPN (closes #20188) | Benjamin Peterson | 2015-01-23 | 1 | -4/+60 | |
| | | | | ||||||
* | | | | enable cert validation in test | Benjamin Peterson | 2015-01-08 | 1 | -1/+4 | |
| | | | | ||||||
* | | | | trying again | Benjamin Peterson | 2015-01-08 | 1 | -2/+2 | |
| | | | | ||||||
* | | | | reorder cipher prefs | Benjamin Peterson | 2015-01-08 | 1 | -1/+1 | |
| | | | | ||||||
* | | | | drop 256 | Benjamin Peterson | 2015-01-08 | 1 | -2/+2 | |
| | | | | ||||||
* | | | | try using AES256 | Benjamin Peterson | 2015-01-08 | 1 | -3/+3 | |
| | | | | ||||||
* | | | | fix assertions after ciphers were changed | Benjamin Peterson | 2015-01-07 | 1 | -2/+1 | |
| | | | | ||||||
* | | | | rc4 is a long time favorite | Benjamin Peterson | 2015-01-07 | 1 | -2/+2 | |
| | | | | ||||||
* | | | | everyone should support AES ciphers | Benjamin Peterson | 2015-01-07 | 1 | -3/+4 | |
| | | | | ||||||
* | | | | include some more ciphers | Benjamin Peterson | 2015-01-07 | 1 | -3/+3 | |
| | | | | ||||||
* | | | | force test server to speak tlsv1 | Benjamin Peterson | 2015-01-07 | 1 | -1/+1 | |
| | | | | ||||||
* | | | | remove apparently wrong assertion about des bit size | Benjamin Peterson | 2015-01-07 | 1 | -1/+0 | |
| | | | | ||||||
* | | | | expose the client's cipher suites from the handshake (closes #23186) | Benjamin Peterson | 2015-01-07 | 1 | -0/+17 | |
| | | | | ||||||
* | | | | test_ssl: add more debug to investigate test_openssl_version() failure on | Victor Stinner | 2015-01-06 | 1 | -2/+2 | |
| | | | | | | | | | | | | | | | | OpenBSD with LibreSSL. | |||||
* | | | | Issue #22935: Fix test_ssl when the SSLv3 protocol is not supported | Victor Stinner | 2014-12-12 | 1 | -3/+4 | |
| | | | | ||||||
* | | | | merge 3.4 (#22935) | Benjamin Peterson | 2014-12-06 | 1 | -7/+16 | |
|\ \ \ \ | |/ / / | ||||||
| * | | | allow ssl module to compile if openssl doesn't support SSL 3 (closes #22935) | Benjamin Peterson | 2014-12-06 | 1 | -7/+16 | |
| | | | | | | | | | | | | | | | | Patch by Kurt Roeckx. | |||||
* | | | | Issue #21356: Make ssl.RAND_egd() optional to support LibreSSL. The | Victor Stinner | 2014-11-28 | 1 | -2/+3 | |
| | | | | | | | | | | | | | | | | | | | | | | | | availability of the function is checked during the compilation. Patch written by Bernard Spil. | |||||
* | | | | merge 3.4 (#22921) | Benjamin Peterson | 2014-11-23 | 1 | -12/+4 | |
|\ \ \ \ | |/ / / | ||||||
| * | | | don't require OpenSSL SNI to pass hostname to ssl functions (#22921) | Benjamin Peterson | 2014-11-23 | 1 | -6/+2 | |
| | | | | | | | | | | | | | | | | Patch by Donald Stufft. | |||||
* | | | | merge 3.4 | Benjamin Peterson | 2014-11-04 | 1 | -1/+1 | |
|\ \ \ \ | |/ / / | ||||||
| * | | | test that keyfile can be None | Benjamin Peterson | 2014-11-04 | 1 | -1/+1 | |
| | | | | ||||||
* | | | | merge 3.4 (#22417) | Benjamin Peterson | 2014-11-03 | 1 | -3/+4 | |
|\ \ \ \ | |/ / / | ||||||
| * | | | PEP 476: enable HTTPS certificate verification by default (#22417) | Benjamin Peterson | 2014-11-03 | 1 | -3/+4 | |
| | | | | | | | | | | | | | | | | Patch by Alex Gaynor with some modifications by me. | |||||
* | | | | Issue #21965: Add support for in-memory SSL to the ssl module. | Antoine Pitrou | 2014-10-05 | 1 | -2/+160 | |
| | | | | | | | | | | | | | | | | Patch by Geert Jansen. | |||||
* | | | | merge 3.4 | Benjamin Peterson | 2014-10-03 | 1 | -0/+15 | |
|\ \ \ \ | |/ / / | ||||||
| * | | | separate cert loading tests into Windows and non-Windows cases | Benjamin Peterson | 2014-10-03 | 1 | -0/+15 | |
| | | | | ||||||
* | | | | merge 3.4 (#22449) | Benjamin Peterson | 2014-10-03 | 1 | -0/+8 | |
|\ \ \ \ | |/ / / |