New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade installers to OpenSSL 1.0.2j #72435
Comments
1.0.2i passes all tests of 2.7, 3.5-7 on Linux |
Make that OpenSSL 1.0.2j with fix for CVE-2016-7052 |
We didn't get this into 3.6.0b2; needs to be in 3.6.0b3. |
Hi, I updated the openssl version from 1.0.2h to 1.0.2j in build-installer.py Please let me know if this works. Thanks :) |
New changeset c29045efd25e by Zachary Ware in branch '2.7': New changeset d7b9ce8ae79b by Zachary Ware in branch '3.4': New changeset 5fa74d8c987b by Zachary Ware in branch '3.5': New changeset cc5006dab787 by Zachary Ware in branch '3.6': New changeset fea9ff9e745d by Zachary Ware in branch 'default': |
@zach maybe we can close this issue if you have updated openssl ? |
The Mac installer still needs to be updated, which is Ned's department. |
ok, thank you Zach for this comment. |
New changeset 33ad26897e30 by Ned Deily in branch '2.7': New changeset a8799a63feb7 by Ned Deily in branch '3.5': New changeset c7e551f8c5d8 by Ned Deily in branch '3.6': New changeset 9e66ffa7a791 by Ned Deily in branch 'default': |
Thanks for the patch, Mariatta. Pushed for released in 2.7.13, 3.5.3, and 3.6.0b3. |
From the changelog I interpreted this to mean that Python would now use OpenSSL 1.0.2j on macOS for it's ssl module. Python 2.7.13rc1 (v2.7.13rc1:4d6fd49eeb14, Dec 3 2016, 13:01:23)
[GCC 4.2.1 (Apple Inc. build 5666) (dot 3)] on darwin
Type "help", "copyright", "credits" or "license" for more information.
>>> import ssl
>>> ssl.OPENSSL_VERSION
'OpenSSL 0.9.8zh 14 Jan 2016' |
@s Safihre. See the ReadMe included with the python.org 2.7.x installers. (It is displayed at installation and a copy is installed to /Applications/Python 2.7/ReadMe.rtf) As explained there, for 2.7.13rc1 as in recent previous 2.7.x releases, only the 10.5+ installer variant is linked with the private copy of OpenSSL; the 10.6+ installer uses the Apple-supplied system version. |
Misc/NEWS
so that it is managed by towncrier #552Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields:
The text was updated successfully, but these errors were encountered: