Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
Undo Debian Unstable's patching for SSL_CTX. Allow all protocols with
SSL_CTX_set_min_proto_version() again so they can be enabled and disabled
with SSL_CTX_set_options(). The set_min_proto_version is not supported by
Python, set_options is available as SSLContext.options.
28 changes: 28 additions & 0 deletions 28 Modules/_ssl.c
Original file line number Diff line number Diff line change
Expand Up @@ -2746,6 +2746,34 @@ _ssl__SSLContext_impl(PyTypeObject *type, int proto_version)
return NULL;
}

#ifdef SSL_CTX_set_min_proto_version
/* Workaround for Debian's OpenSSL patch
*
* Debian disables SSL 3.0, TLS 1.0, and TLS 1.1 by default. Python
* does not expose the new OpenSSL 1.1 API that is required to
* re-enable the old protocols. Documentation also promises that
* PROTOCOL_TLS has TLS 1.0 and 1.1 enabled and SSLv3 can be enabled
* by changing SSLContext.options.
*/
if ((proto_version == PY_SSL_VERSION_TLS) ||
(proto_version == PY_SSL_VERSION_TLS_CLIENT) ||
(proto_version == PY_SSL_VERSION_TLS_SERVER)) {
#if !defined(OPENSSL_NO_SSL3)
result = SSL_CTX_set_min_proto_version(ctx, SSL3_VERSION);
#elif !defined(OPENSSL_NO_TLS1)
result = SSL_CTX_set_min_proto_version(ctx, TLS1_VERSION);
#elif !defined(OPENSSL_NO_TLS1_1)
result = SSL_CTX_set_min_proto_version(ctx, TLS1_1_VERSION);
#else
result = 1;
#endif
if (result == 0) {
_setSSLError(NULL, 0, __FILE__, __LINE__);
return NULL;
}
}
#endif /* SSL_CTX_set_min_proto_version */

assert(type != NULL && type->tp_alloc != NULL);
self = (PySSLContext *) type->tp_alloc(type, 0);
if (self == NULL) {
Expand Down
Morty Proxy This is a proxified and sanitized view of the page, visit original site.