Message213425
It's great that Christian did all the work he did on the SSL module to enhance its security capabilities, and great that Antoine did the work he did before that. Now we need an explanation of how best to use it all :)
It is not clear from the existing documentation how to best use the various standard library modules that support SSL in a "best practices" way. Perhaps this could go in the SSL docs and be linked from all the library components that use it. Alternatively we could perhaps have a general security overview chapter in the library reference, but we at least an SSL one. The existing documentation in the SSL module, while it contains a lot of information about the available, doesn't make it clear what a programmer should actually *do*. As one example, it is not clear when or even if an application programmer would call check_hostname. |
|
Date |
User |
Action |
Args |
2014-03-13 17:56:27 | r.david.murray | set | recipients:
+ r.david.murray, pitrou, vstinner, christian.heimes |
2014-03-13 17:56:27 | r.david.murray | set | messageid: <1394733387.87.0.332479882256.issue20913@psf.upfronthosting.co.za> |
2014-03-13 17:56:27 | r.david.murray | link | issue20913 messages |
2014-03-13 17:56:27 | r.david.murray | create | |
|