
This issue trackerhas been migrated toGitHub, and is currentlyread-only.
For more information, see the GitHub FAQs in the Python's Developer Guide.
Created on2014-03-23 23:50 byalex, last changed2022-04-11 14:58 byadmin. This issue is nowclosed.
| Files | ||||
|---|---|---|---|---|
| File name | Uploaded | Description | Edit | |
| cacert.diff | alex,2014-03-23 23:50 | review | ||
| cacert.diff | alex,2014-03-24 00:10 | review | ||
| cacert.diff | alex,2014-03-24 00:11 | review | ||
| Messages (11) | |||
|---|---|---|---|
| msg214656 -(view) | Author: Alex Gaynor (alex)*![]() | Date: 2014-03-23 23:50 | |
CACert is not in the root trust store on *any* platform that I'm aware of, and has not passed any audits. Seehttp://lwn.net/SubscriberLink/590879/ce23ed7bab68e489/ for more background.In it's place I've added StartSSL, which is included in most (all?) root trust stores, and offers free certs. | |||
| msg214657 -(view) | Author: Donald Stufft (dstufft)*![]() | Date: 2014-03-23 23:51 | |
I completely agree, it seems less than good to recommend CACert. | |||
| msg214658 -(view) | Author: Antoine Pitrou (pitrou)*![]() | Date: 2014-03-24 00:01 | |
That whole paragraph in the documentation is weird. Usually, you don't download select root certificates from various CAs, you just elect to trust a predetermined set of root certs (the system ones, usually).I would suggest rewording it and dropping the various download URLs.(and if the suggestion to provide the full chain is obsolete for SSLv3 and TLSv1, then similarly it may be dropped entirely - we needn't support SSLv2 specificities in the docs) | |||
| msg214659 -(view) | Author: Donald Stufft (dstufft)*![]() | Date: 2014-03-24 00:02 | |
It's quite old (that paragraph) likely it was written that way because back then Python didn't have a way to load certificates. | |||
| msg214660 -(view) | Author: Alex Gaynor (alex)*![]() | Date: 2014-03-24 00:10 | |
I've attempted to modernize the paragraph. | |||
| msg214661 -(view) | Author: Alex Gaynor (alex)*![]() | Date: 2014-03-24 00:10 | |
Removed 2.7 since there's no API for getting the platform certs. | |||
| msg214698 -(view) | Author: Donald Stufft (dstufft)*![]() | Date: 2014-03-24 16:49 | |
The latest patch looks good to me. | |||
| msg214700 -(view) | Author: Antoine Pitrou (pitrou)*![]() | Date: 2014-03-24 17:01 | |
Looks good to me too. | |||
| msg214762 -(view) | Author: Roundup Robot (python-dev)![]() | Date: 2014-03-24 23:27 | |
New changeset6f776c91da08 by Donald Stufft in branch '3.4':Issue#21043: Remove the recommendation for specific CA organizationshttp://hg.python.org/cpython/rev/6f776c91da08 | |||
| msg214764 -(view) | Author: Roundup Robot (python-dev)![]() | Date: 2014-03-24 23:28 | |
New changeset0485552b487e by Donald Stufft in branch 'default':Merge in 3.4 to bring forward the Issue#21043 changes.http://hg.python.org/cpython/rev/0485552b487e | |||
| msg214768 -(view) | Author: Roundup Robot (python-dev)![]() | Date: 2014-03-24 23:49 | |
New changeset7ef262eafecd by Donald Stufft in branch '2.7':Issue#21043 - Remove CACert.org from the recommendationshttp://hg.python.org/cpython/rev/7ef262eafecd | |||
| History | |||
|---|---|---|---|
| Date | User | Action | Args |
| 2022-04-11 14:58:00 | admin | set | github: 65242 |
| 2014-03-24 23:49:56 | python-dev | set | messages: +msg214768 |
| 2014-03-24 23:29:29 | dstufft | set | status: open -> closed resolution: fixed |
| 2014-03-24 23:28:27 | python-dev | set | messages: +msg214764 |
| 2014-03-24 23:27:08 | python-dev | set | nosy: +python-dev messages: +msg214762 |
| 2014-03-24 17:01:43 | pitrou | set | messages: +msg214700 |
| 2014-03-24 16:49:27 | dstufft | set | messages: +msg214698 |
| 2014-03-24 00:23:54 | BreamoreBoy | set | title: Stop reccomending CACert.org in the SSL documentation -> Stop recommending CACert.org in the SSL documentation |
| 2014-03-24 00:11:24 | alex | set | files: +cacert.diff |
| 2014-03-24 00:10:54 | alex | set | messages: +msg214661 versions: - Python 2.7 |
| 2014-03-24 00:10:32 | alex | set | files: +cacert.diff messages: +msg214660 |
| 2014-03-24 00:02:48 | dstufft | set | messages: +msg214659 |
| 2014-03-24 00:01:24 | pitrou | set | nosy: +pitrou messages: +msg214658 |
| 2014-03-23 23:52:34 | alex | set | versions: + Python 2.7, Python 3.4, Python 3.5 |
| 2014-03-23 23:51:17 | dstufft | set | messages: +msg214657 |
| 2014-03-23 23:50:30 | alex | create | |