Kaydet (Commit) 79ecd762 authored tarafından Antoine Pitrou's avatar Antoine Pitrou

Issue #9983: warn that urllib and httplib don't perform SSL certificate validation.

üst c3ed2e7f
...@@ -53,13 +53,13 @@ The module provides the following classes: ...@@ -53,13 +53,13 @@ The module provides the following classes:
.. class:: HTTPSConnection(host, port=None, key_file=None, cert_file=None, strict=None[, timeout[, source_address]]) .. class:: HTTPSConnection(host, port=None, key_file=None, cert_file=None, strict=None[, timeout[, source_address]])
A subclass of :class:`HTTPConnection` that uses SSL for communication with A subclass of :class:`HTTPConnection` that uses SSL for communication with
secure servers. Default port is ``443``. *key_file* is the name of a PEM secure servers. Default port is ``443``. *key_file* is the name of a PEM
formatted file that contains your private key. *cert_file* is a PEM formatted formatted file that contains your private key, and *cert_file* is a PEM
certificate chain file. formatted certificate chain file; both can be used for authenticating
yourself against the server.
.. note:: .. warning::
This does not do any verification of the server's certificate.
This does not do any certificate verification.
.. versionchanged:: 3.2 .. versionchanged:: 3.2
*source_address* was added. *source_address* was added.
......
...@@ -11,6 +11,10 @@ The :mod:`urllib.request` module defines functions and classes which help in ...@@ -11,6 +11,10 @@ The :mod:`urllib.request` module defines functions and classes which help in
opening URLs (mostly HTTP) in a complex world --- basic and digest opening URLs (mostly HTTP) in a complex world --- basic and digest
authentication, redirections, cookies and more. authentication, redirections, cookies and more.
.. warning:: When opening HTTPS (or FTPS) URLs, it is not attempted to
validate the server certificate. Use at your own risk!
The :mod:`urllib.request` module defines the following functions: The :mod:`urllib.request` module defines the following functions:
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment