Thanks to visit codestin.com
Credit goes to github.com

Skip to content

[3.7] bpo-41561: Add workaround for Ubuntu's custom security level (GH-24915) #24928

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 3, 2021

Conversation

tiran
Copy link
Member

@tiran tiran commented Mar 18, 2021

Ubuntu 20.04 comes with a patched OpenSSL 1.1.1. Default security level
2 blocks TLS 1.0 and 1.1 connections. Regular OpenSSL 1.1.1 builds allow
TLS 1.0 and 1.1 on security level 2.

See:
See: https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1899878
See: https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1917625
Signed-off-by: Christian Heimes [email protected].
(cherry picked from commit f6c6b58)

Co-authored-by: Christian Heimes [email protected]

https://bugs.python.org/issue41561

…ythonGH-24915)

Ubuntu 20.04 comes with a patched OpenSSL 1.1.1. Default security level
2 blocks TLS 1.0 and 1.1 connections. Regular OpenSSL 1.1.1 builds allow
TLS 1.0 and 1.1 on security level 2.

See:
See: https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1899878
See: https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1917625
Signed-off-by: Christian Heimes <[email protected]>.
(cherry picked from commit f6c6b58)

Co-authored-by: Christian Heimes <[email protected]>
@ned-deily
Copy link
Member

ned-deily commented Mar 20, 2021

@tiran Technically, this change does not seem to meet the criteria for a release in its security-fix-only phase. But it seems reasonable enough to simplify CI issues etc. If we allow it for 3.7, then what about for 3.6 which is also still in its security-fix-only phase?

@tiran
Copy link
Member Author

tiran commented Apr 17, 2021

@ned-deily yeah, it makes sense to backport the workaround to 3.6, too.

@ned-deily
Copy link
Member

Looking more closely at this, it does not backport cleanly to 3.6 and I don't think it's worth the effort.

@ned-deily ned-deily merged commit 64be96a into python:3.7 May 3, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants