Title: distutils should check PyPI certs when connecting to it
Type: security Stage:
Components: Library (Lib) Versions: Python 3.2, Python 3.3, Python 3.4, Python 2.7
Status: closed Resolution: fixed
Dependencies: Superseder:
Assigned To: Nosy List: Giovanni.Bajo, alexis, benjamin.peterson, christian.heimes, cvrebert, dstufft, eric.araujo, georg.brandl, jwilk, pitrou, tiwilliam
Priority: high Keywords:

Created on 2013-12-22 00:52 by pitrou, last changed 2022-04-11 14:57 by admin.

Messages (2)
msg206800 - (view) Author: Antoine Pitrou (pitrou) * (Python committer) Date: 2013-12-22 00:52
Spun off from #12226: distutils now uses HTTPS by default to connect PyPI, but certs aren't checked at all.
msg275222 - (view) Author: Christian Heimes (christian.heimes) * (Python committer) Date: 2016-09-08 23:59
distutils uses urlopen() which uses ssl.create_default_context() to create a SSLContext with cert validation and hostname verification enabled.
