diff options
author | Benjamin Peterson <benjamin@python.org> | 2014-10-03 17:27:05 -0400 |
---|---|---|
committer | Benjamin Peterson <benjamin@python.org> | 2014-10-03 17:27:05 -0400 |
commit | 5915b0f924152b4801c1fe49aff348fd1981cc05 (patch) | |
tree | fd507980526910467e5f213624f12d41471f18bd | |
parent | 7280561b5b2363c50797fbec301fefcd1e5a8040 (diff) | |
download | cpython-git-5915b0f924152b4801c1fe49aff348fd1981cc05.tar.gz |
also use openssl envvars to find certs on windows (closes #22449)
Patch by Christian Heimes and Alex Gaynor.
-rw-r--r-- | Lib/ssl.py | 3 | ||||
-rw-r--r-- | Lib/test/test_ssl.py | 8 | ||||
-rw-r--r-- | Misc/NEWS | 3 |
3 files changed, 12 insertions, 2 deletions
diff --git a/Lib/ssl.py b/Lib/ssl.py index d3c18ed1b7..d9d191628c 100644 --- a/Lib/ssl.py +++ b/Lib/ssl.py @@ -390,8 +390,7 @@ class SSLContext(_SSLContext): if sys.platform == "win32": for storename in self._windows_cert_stores: self._load_windows_store_certs(storename, purpose) - else: - self.set_default_verify_paths() + self.set_default_verify_paths() def create_default_context(purpose=Purpose.SERVER_AUTH, *, cafile=None, diff --git a/Lib/test/test_ssl.py b/Lib/test/test_ssl.py index d1cf5b2794..c2a4f0e811 100644 --- a/Lib/test/test_ssl.py +++ b/Lib/test/test_ssl.py @@ -1016,6 +1016,14 @@ class ContextTests(unittest.TestCase): self.assertRaises(TypeError, ctx.load_default_certs, None) self.assertRaises(TypeError, ctx.load_default_certs, 'SERVER_AUTH') + def test_load_default_certs_env(self): + ctx = ssl.SSLContext(ssl.PROTOCOL_TLSv1) + with support.EnvironmentVarGuard() as env: + env["SSL_CERT_DIR"] = CAPATH + env["SSL_CERT_FILE"] = CERTFILE + ctx.load_default_certs() + self.assertEqual(ctx.cert_store_stats(), {"crl": 0, "x509": 1, "x509_ca": 0}) + def test_create_default_context(self): ctx = ssl.create_default_context() self.assertEqual(ctx.protocol, ssl.PROTOCOL_SSLv23) @@ -19,6 +19,9 @@ Core and Builtins Library ------- +- Issue #22449: In the ssl.SSLContext.load_default_certs, consult the + enviromental variables SSL_CERT_DIR and SSL_CERT_FILE on Windows. + - Issue #20076: Added non derived UTF-8 aliases to locale aliases table. - Issue #20079: Added locales supported in glibc 2.18 to locale alias table. |