From 77a75b3db1b3c63833067f6864e62dcf312ded05 Mon Sep 17 00:00:00 2001 From: Benjamin Peterson Date: Mon, 13 Oct 2014 11:54:50 -0400 Subject: note xmlrpclib doesn't verify certs (yet) --- Doc/library/xmlrpc.client.rst | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/Doc/library/xmlrpc.client.rst b/Doc/library/xmlrpc.client.rst index 3cb19d1..6471ba2 100644 --- a/Doc/library/xmlrpc.client.rst +++ b/Doc/library/xmlrpc.client.rst @@ -27,6 +27,11 @@ between conformable Python objects and XML on the wire. constructed data. If you need to parse untrusted or unauthenticated data see :ref:`xml-vulnerabilities`. +.. warning:: + + In the case of https URIS, :mod:`xmlrpc.client` does not do any verification + of the server's certificate. + .. class:: ServerProxy(uri, transport=None, encoding=None, verbose=False, \ allow_none=False, use_datetime=False, \ -- cgit v0.12