<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/cpython-git.git/Tools/ssl, branch fix-misc-acks</title>
<subtitle>github.com: python/cpython.git
</subtitle>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/'/>
<entry>
<title>[3.7] bpo-38117: Test with OpenSSL 1.1.1d (GH-15983) (GH-15994)</title>
<updated>2019-09-11T17:36:06+00:00</updated>
<author>
<name>Stéphane Wirtel</name>
<email>stephane@wirtel.be</email>
</author>
<published>2019-09-11T17:36:06+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=cec68c31e8507159534b6eec3fb5d801cd3dbf8c'/>
<id>cec68c31e8507159534b6eec3fb5d801cd3dbf8c</id>
<content type='text'>
Signed-off-by: Christian Heimes &lt;christian@python.org&gt;.
(cherry picked from commit 58ab13479d854491ac9207bacfae25e8b18b044a)

Co-authored-by: Christian Heimes &lt;christian@python.org&gt;


https://bugs.python.org/issue38117



Automerge-Triggered-By: @matrixise</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Signed-off-by: Christian Heimes &lt;christian@python.org&gt;.
(cherry picked from commit 58ab13479d854491ac9207bacfae25e8b18b044a)

Co-authored-by: Christian Heimes &lt;christian@python.org&gt;


https://bugs.python.org/issue38117



Automerge-Triggered-By: @matrixise</pre>
</div>
</content>
</entry>
<entry>
<title>[3.7] bpo-37081: Test with OpenSSL 1.1.1c (GH-13631) (GH-13782)</title>
<updated>2019-06-03T18:39:57+00:00</updated>
<author>
<name>Miss Islington (bot)</name>
<email>31488909+miss-islington@users.noreply.github.com</email>
</author>
<published>2019-06-03T18:39:57+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=3344197040fe1b05a3244bdb16d429f4647f35b8'/>
<id>3344197040fe1b05a3244bdb16d429f4647f35b8</id>
<content type='text'>
Signed-off-by: Christian Heimes &lt;christian@python.org&gt;
(cherry picked from commit 06651ee418b5e4e013195d6b702763a1220706a7)


Co-authored-by: Christian Heimes &lt;christian@python.org&gt;


https://bugs.python.org/issue37081</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Signed-off-by: Christian Heimes &lt;christian@python.org&gt;
(cherry picked from commit 06651ee418b5e4e013195d6b702763a1220706a7)


Co-authored-by: Christian Heimes &lt;christian@python.org&gt;


https://bugs.python.org/issue37081</pre>
</div>
</content>
</entry>
<entry>
<title>[3.7] bpo-34670: Add TLS 1.3 post handshake auth (GH-9460) (GH-9505)</title>
<updated>2018-09-23T07:22:52+00:00</updated>
<author>
<name>Christian Heimes</name>
<email>christian@python.org</email>
</author>
<published>2018-09-23T07:22:52+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=2756ef31656399a120589b7aa19c32e2b91a4758'/>
<id>2756ef31656399a120589b7aa19c32e2b91a4758</id>
<content type='text'>
Add SSLContext.post_handshake_auth and
SSLSocket.verify_client_post_handshake for TLS 1.3 post-handshake
authentication.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;q

https://bugs.python.org/issue34670.
(cherry picked from commit 9fb051f032c36b9f6086b79086b4d6b7755a3d70)

Co-authored-by: Christian Heimes &lt;christian@python.org&gt;



https://bugs.python.org/issue34670</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Add SSLContext.post_handshake_auth and
SSLSocket.verify_client_post_handshake for TLS 1.3 post-handshake
authentication.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;q

https://bugs.python.org/issue34670.
(cherry picked from commit 9fb051f032c36b9f6086b79086b4d6b7755a3d70)

Co-authored-by: Christian Heimes &lt;christian@python.org&gt;



https://bugs.python.org/issue34670</pre>
</div>
</content>
</entry>
<entry>
<title>[3.7] bpo-33618: Enable TLS 1.3 in tests (GH-7079) (GH-7082)</title>
<updated>2018-05-23T20:49:04+00:00</updated>
<author>
<name>Miss Islington (bot)</name>
<email>31488909+miss-islington@users.noreply.github.com</email>
</author>
<published>2018-05-23T20:49:04+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=72ef4fc32b354f8e56eec64f4c15ac2e07d118be'/>
<id>72ef4fc32b354f8e56eec64f4c15ac2e07d118be</id>
<content type='text'>
TLS 1.3 behaves slightly different than TLS 1.2. Session tickets and TLS
client cert auth are now handled after the initialy handshake. Tests now
either send/recv data to trigger session and client certs. Or tests
ignore ConnectionResetError / BrokenPipeError on the server side to
handle clients that force-close the socket fd.

To test TLS 1.3, OpenSSL 1.1.1-pre7-dev (git master + OpenSSL PR
https://github.com/openssl/openssl/pull/6340) is required.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;
(cherry picked from commit 529525fb5a8fd9b96ab4021311a598c77588b918)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
TLS 1.3 behaves slightly different than TLS 1.2. Session tickets and TLS
client cert auth are now handled after the initialy handshake. Tests now
either send/recv data to trigger session and client certs. Or tests
ignore ConnectionResetError / BrokenPipeError on the server side to
handle clients that force-close the socket fd.

To test TLS 1.3, OpenSSL 1.1.1-pre7-dev (git master + OpenSSL PR
https://github.com/openssl/openssl/pull/6340) is required.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;
(cherry picked from commit 529525fb5a8fd9b96ab4021311a598c77588b918)
</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-33570: TLS 1.3 ciphers for OpenSSL 1.1.1 (GH-6976)</title>
<updated>2018-05-22T21:40:46+00:00</updated>
<author>
<name>Miss Islington (bot)</name>
<email>31488909+miss-islington@users.noreply.github.com</email>
</author>
<published>2018-05-22T21:40:46+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=cd57b48ef9a70b7ef693ba52aaf38d7c945ab5d3'/>
<id>cd57b48ef9a70b7ef693ba52aaf38d7c945ab5d3</id>
<content type='text'>
Change TLS 1.3 cipher suite settings for compatibility with OpenSSL
1.1.1-pre6 and newer. OpenSSL 1.1.1 will have TLS 1.3 cipers enabled by
default.

Also update multissltests and Travis config to test with latest OpenSSL.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;
(cherry picked from commit e8eb6cb7920ded66abc5d284319a8539bdc2bae3)

Co-authored-by: Christian Heimes &lt;christian@python.org&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change TLS 1.3 cipher suite settings for compatibility with OpenSSL
1.1.1-pre6 and newer. OpenSSL 1.1.1 will have TLS 1.3 cipers enabled by
default.

Also update multissltests and Travis config to test with latest OpenSSL.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;
(cherry picked from commit e8eb6cb7920ded66abc5d284319a8539bdc2bae3)

Co-authored-by: Christian Heimes &lt;christian@python.org&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-33522: Enable CI builds on Visual Studio Team Services (GH-6865) (GH-6926)</title>
<updated>2018-05-17T12:49:01+00:00</updated>
<author>
<name>Miss Islington (bot)</name>
<email>31488909+miss-islington@users.noreply.github.com</email>
</author>
<published>2018-05-17T12:49:01+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=8965d75c90e80b6983b36f3ae9601d6a257d782b'/>
<id>8965d75c90e80b6983b36f3ae9601d6a257d782b</id>
<content type='text'>
(cherry picked from commit e5f41d2f1e0b8b8e61d5fa427c19bd1ea90fd9a3)

Co-authored-by: Steve Dower &lt;steve.dower@microsoft.com&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
(cherry picked from commit e5f41d2f1e0b8b8e61d5fa427c19bd1ea90fd9a3)

Co-authored-by: Steve Dower &lt;steve.dower@microsoft.com&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>[3.7] bpo-33127: Compatibility patch for LibreSSL 2.7.0 (GH-6210) (GH-6213)</title>
<updated>2018-03-24T17:37:54+00:00</updated>
<author>
<name>Miss Islington (bot)</name>
<email>31488909+miss-islington@users.noreply.github.com</email>
</author>
<published>2018-03-24T17:37:54+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=42bd62bc87a52538c0fc2134b76df316f30997da'/>
<id>42bd62bc87a52538c0fc2134b76df316f30997da</id>
<content type='text'>
LibreSSL 2.7 introduced OpenSSL 1.1.0 API. The ssl module now detects
LibreSSL 2.7 and only provides API shims for OpenSSL &lt; 1.1.0 and
LibreSSL &lt; 2.7.

Documentation updates and fixes for failing tests will be provided in
another patch set.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;
(cherry picked from commit 4ca0739c9d97ac7cd45499e0d31be68dc659d0e1)

Co-authored-by: Christian Heimes &lt;christian@python.org&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
LibreSSL 2.7 introduced OpenSSL 1.1.0 API. The ssl module now detects
LibreSSL 2.7 and only provides API shims for OpenSSL &lt; 1.1.0 and
LibreSSL &lt; 2.7.

Documentation updates and fixes for failing tests will be provided in
another patch set.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;
(cherry picked from commit 4ca0739c9d97ac7cd45499e0d31be68dc659d0e1)

Co-authored-by: Christian Heimes &lt;christian@python.org&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-32947: OpenSSL 1.1.1-pre1 / TLS 1.3 fixes (GH-5663)</title>
<updated>2018-02-27T08:17:49+00:00</updated>
<author>
<name>Miss Islington (bot)</name>
<email>31488909+miss-islington@users.noreply.github.com</email>
</author>
<published>2018-02-27T08:17:49+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=2614ed4c6e4b32eafb683f2378ed20e87d42976d'/>
<id>2614ed4c6e4b32eafb683f2378ed20e87d42976d</id>
<content type='text'>
* bpo-32947: OpenSSL 1.1.1-pre1 / TLS 1.3 fixes

Misc fixes and workarounds for compatibility with OpenSSL 1.1.1-pre1 and
TLS 1.3 support. With OpenSSL 1.1.1, Python negotiates TLS 1.3 by
default. Some test cases only apply to TLS 1.2. Other tests currently
fail because the threaded or async test servers stop after failure.

I'm going to address these issues when OpenSSL 1.1.1 reaches beta.

OpenSSL 1.1.1 has added a new option OP_ENABLE_MIDDLEBOX_COMPAT for TLS
1.3. The feature is enabled by default for maximum compatibility with
broken middle boxes. Users should be able to disable the hack and CPython's test suite needs
it to verify default options.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;
(cherry picked from commit 05d9fe32a1245b9a798e49e0c1eb91f110935b69)

Co-authored-by: Christian Heimes &lt;christian@python.org&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* bpo-32947: OpenSSL 1.1.1-pre1 / TLS 1.3 fixes

Misc fixes and workarounds for compatibility with OpenSSL 1.1.1-pre1 and
TLS 1.3 support. With OpenSSL 1.1.1, Python negotiates TLS 1.3 by
default. Some test cases only apply to TLS 1.2. Other tests currently
fail because the threaded or async test servers stop after failure.

I'm going to address these issues when OpenSSL 1.1.1 reaches beta.

OpenSSL 1.1.1 has added a new option OP_ENABLE_MIDDLEBOX_COMPAT for TLS
1.3. The feature is enabled by default for maximum compatibility with
broken middle boxes. Users should be able to disable the hack and CPython's test suite needs
it to verify default options.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;
(cherry picked from commit 05d9fe32a1245b9a798e49e0c1eb91f110935b69)

Co-authored-by: Christian Heimes &lt;christian@python.org&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-32549: Compile OpenSSL 1.1.0 on Travis CI (#5180)</title>
<updated>2018-01-16T20:02:26+00:00</updated>
<author>
<name>Christian Heimes</name>
<email>christian@python.org</email>
</author>
<published>2018-01-16T20:02:26+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=ced9cb5303ad1447f84d923e0c7f769f5e0c6297'/>
<id>ced9cb5303ad1447f84d923e0c7f769f5e0c6297</id>
<content type='text'>
Use an improved version of multissl test helper to compile a local copy
of OpenSSL 1.1.0g.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Use an improved version of multissl test helper to compile a local copy
of OpenSSL 1.1.0g.

Signed-off-by: Christian Heimes &lt;christian@python.org&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>Update multissltests: 1.0.2m, 1.1.0g (#4232)</title>
<updated>2017-11-02T16:38:11+00:00</updated>
<author>
<name>Christian Heimes</name>
<email>christian@python.org</email>
</author>
<published>2017-11-02T16:38:11+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=0d2c645d41eee4ec7549c86ccc23970b692a48b0'/>
<id>0d2c645d41eee4ec7549c86ccc23970b692a48b0</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
