SSLContext loads certificates from the "CA" Intermediate certificate store.
还没有人认领这个 Issue。
- 主要语言
- Python
- 星标
- 77.2k
- 派生
- 35.9k
- PR 合并指标
- PR 指标待抓取
描述
Bug report
Bug description:
ssl.py
class SSLContext(_SSLContext):
"""An SSLContext holds various SSL-related configuration options and
data, such as certificates and possibly a private key."""
_windows_cert_stores = ("CA", "ROOT")
When a certificate is imported into the windows "Intermediate Certification Authorities" most applications do not consider this a trusted CA and will fail to verify. Examples are the chrome browser and .Net Applications.
This can be tested using - https://untrusted-root.badssl.com/ and downloading the public key and importing into the "Intermediate Certificate Authorities".
Cert = Windows CertMgr Name
Root = Trusted Root Certification Authorities
CA = Intermediate Certification Authorities
Given that other applications (chrome, .Net) seem to not treat "CA" certificates as a trusted root, should python load these by default?
Use Case:
Using requests Adapter to load the windows certificates rather than rely on Certifi.
https://requests.readthedocs.io/en/latest/user/advanced/#:~:text=10%27%2C%20%27rel%27%3A%20%27last%27%7D-,Transport%20Adapters%C2%B6,-As%20of%20v1.0.0
class WindowsSSLContextAdapter(HTTPAdapter):
def __init__(self, url_prefix):
self.url_prefix = url_prefix
super().__init__()
def init_poolmanager(self, *args, **kwargs):
# loads CA and ROOT certificates on windows
context = ssl.create_default_context()
kwargs['ssl_context'] = context
return super().init_poolmanager(*args, **kwargs)
#Mount the HTTPAdapter on requests session
session.mount(url_prefix, adapter)
CPython versions tested on:
3.11
Operating systems tested on:
Windows
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从 ssl.py 中的 SSLContext._windows_cert_stores 开始,跟踪 create_default_context() 如何加载 Windows 证书存储。将当前的 CA 和 ROOT 行为与报告中所述的 Windows 信任语义以及现有的平台特定覆盖范围进行比较。当默认的证书加载行为符合预期的信任模型,并由适当的 Windows 测试覆盖时,即表示完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- python
- 领域
- networking, security
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 42/100