SSLContext loads certificates from the "CA" Intermediate certificate store.
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 77.2k
- Forks
- 35.9k
- PR merge metrics
- PR metrics pending
Description
Bug report
Bug description:
ssl.py
class SSLContext(_SSLContext):
"""An SSLContext holds various SSL-related configuration options and
data, such as certificates and possibly a private key."""
_windows_cert_stores = ("CA", "ROOT")
When a certificate is imported into the windows "Intermediate Certification Authorities" most applications do not consider this a trusted CA and will fail to verify. Examples are the chrome browser and .Net Applications.
This can be tested using - https://untrusted-root.badssl.com/ and downloading the public key and importing into the "Intermediate Certificate Authorities".
Cert = Windows CertMgr Name
Root = Trusted Root Certification Authorities
CA = Intermediate Certification Authorities
Given that other applications (chrome, .Net) seem to not treat "CA" certificates as a trusted root, should python load these by default?
Use Case:
Using requests Adapter to load the windows certificates rather than rely on Certifi.
https://requests.readthedocs.io/en/latest/user/advanced/#:~:text=10%27%2C%20%27rel%27%3A%20%27last%27%7D-,Transport%20Adapters%C2%B6,-As%20of%20v1.0.0
class WindowsSSLContextAdapter(HTTPAdapter):
def __init__(self, url_prefix):
self.url_prefix = url_prefix
super().__init__()
def init_poolmanager(self, *args, **kwargs):
# loads CA and ROOT certificates on windows
context = ssl.create_default_context()
kwargs['ssl_context'] = context
return super().init_poolmanager(*args, **kwargs)
#Mount the HTTPAdapter on requests session
session.mount(url_prefix, adapter)
CPython versions tested on:
3.11
Operating systems tested on:
Windows
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in ssl.py at SSLContext._windows_cert_stores and trace how Windows certificate stores are loaded by create_default_context(). Compare the current CA and ROOT behavior with the reported Windows trust semantics and existing platform-specific coverage. Done means the default certificate loading behavior matches the intended trust model and is covered by appropriate Windows tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- networking, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100