{{ message }}
[3.7] bpo-41561: Add workaround for Ubuntu's custom security level (GH-24915)#24928
Merged
ned-deily merged 1 commit intoMay 3, 2021
Merged
[3.7] bpo-41561: Add workaround for Ubuntu's custom security level (GH-24915)#24928ned-deily merged 1 commit into
ned-deily merged 1 commit into
Conversation
…ythonGH-24915) Ubuntu 20.04 comes with a patched OpenSSL 1.1.1. Default security level 2 blocks TLS 1.0 and 1.1 connections. Regular OpenSSL 1.1.1 builds allow TLS 1.0 and 1.1 on security level 2. See: See: https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1899878 See: https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1917625 Signed-off-by: Christian Heimes <christian@python.org>. (cherry picked from commit f6c6b58) Co-authored-by: Christian Heimes <christian@python.org>
Member
|
@tiran Technically, this change does not seem to meet the criteria for a release in its security-fix-only phase. But it seems reasonable enough to simplify CI issues etc. If we allow it for 3.7, then what about for 3.6 which is also still in its security-fix-only phase? |
Sorry, something went wrong.
Member
Author
|
@ned-deily yeah, it makes sense to backport the workaround to 3.6, too. |
Sorry, something went wrong.
Member
|
Looking more closely at this, it does not backport cleanly to 3.6 and I don't think it's worth the effort. |
Sorry, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.
Ubuntu 20.04 comes with a patched OpenSSL 1.1.1. Default security level
2 blocks TLS 1.0 and 1.1 connections. Regular OpenSSL 1.1.1 builds allow
TLS 1.0 and 1.1 on security level 2.
See:
See: https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1899878
See: https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1917625
Signed-off-by: Christian Heimes christian@python.org.
(cherry picked from commit f6c6b58)
Co-authored-by: Christian Heimes christian@python.org
https://bugs.python.org/issue41561