From f7a52475a5f666f7655df4d46f8522e0c5bdc890 Mon Sep 17 00:00:00 2001 From: Antoine Pitrou Date: Sun, 17 Nov 2013 15:42:58 +0100 Subject: Issue #19508: warn that ssl doesn't validate certificates by default --- Doc/library/ssl.rst | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/Doc/library/ssl.rst b/Doc/library/ssl.rst index 898e7d2..fe653b4 100644 --- a/Doc/library/ssl.rst +++ b/Doc/library/ssl.rst @@ -31,6 +31,10 @@ probably additional platforms, as long as OpenSSL is installed on that platform. cause variations in behavior. .. warning:: + The ssl module won't validate certificates by default. When used in + client mode, this means you are vulnerable to man-in-the-middle attacks. + +.. warning:: OpenSSL's internal random number generator does not properly handle fork. Applications must change the PRNG state of the parent process if they use -- cgit v0.12