Announcing txAWS 0.2.3.1

Jean-Paul Calderone <[email protected]> Mon, 9 Jan 2017 12:58:24 -0500
Newsgroups gmane.comp.python.twisted,gmane.comp.python.twisted.web,gmane.comp.python.general
Message-ID <CAEeXt4PSgAGjFbj50=mUytatk5=0tu_UzhV6au+gvqCfWP_a7Q@mail.gmail.com>
--===============3734921720336672141==
Content-Type: multipart/alternative; boundary=94eb2c0481482fb14a0545ad1d50

--94eb2c0481482fb14a0545ad1d50
Content-Type: text/plain; charset=UTF-8

I've just release txAWS 0.2.3.1.  txAWS is a library for interacting with
Amazon Web Services (AWS) using Twisted.

AWSServiceEndpoint's ssl_hostname_verification's parameter now defaults to
True instead of False.  This affects all txAWS APIs which issue requests to
AWS endpoints.  For any application which uses the default
AWSServiceEndpoints, the server's TLS certificate will now be verified.

This resolves a security issue in which txAWS applications were vulnerable
to man-in-the-middle attacks which could either steal sensitive information
or, possibly, alter the AWS operation requested.

The new release is available on PyPI in source and wheel forms.  You can
also find txAWS at its new home on github, <https://github.com/twisted/txaws
>.

Special thanks to Least Authority Enterprises
(<https://leastauthority.com/>) for
sponsoring the work to find and fix this issue and to publish this new
release.

Jean-Paul

--94eb2c0481482fb14a0545ad1d50
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I&#39;ve just release txAWS 0.2.3.1. =C2=A0txAWS is a libr=
ary for interacting with Amazon Web Services (AWS) using Twisted.<div><br><=
/div><div>AWSServiceEndpoint&#39;s ssl_hostname_verification&#39;s paramete=
r now defaults to True instead of False.=C2=A0 This affects all txAWS APIs =
which issue requests to AWS endpoints.=C2=A0 For any application which uses=
 the default AWSServiceEndpoints, the server&#39;s TLS certificate will now=
 be verified.<br></div><div><br></div><div>This resolves a security issue i=
n which txAWS applications were vulnerable to man-in-the-middle attacks whi=
ch could either steal sensitive information or, possibly, alter the AWS ope=
ration requested.</div><div><br></div><div>The new release is available on =
PyPI in source and wheel forms.=C2=A0 You can also find txAWS at its new ho=
me on github, &lt;<a href=3D"https://github.com/twisted/txaws">https://gith=
ub.com/twisted/txaws</a>&gt;.</div><div><br></div><div>Special thanks to Le=
ast Authority Enterprises (&lt;<a href=3D"https://leastauthority.com/">http=
s://leastauthority.com/</a>&gt;)=C2=A0for sponsoring the work to find and f=
ix this issue and to publish this new release.</div><div><br></div><div>Jea=
n-Paul</div><div><br></div></div>

--94eb2c0481482fb14a0545ad1d50--


--===============3734921720336672141==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Twisted-Python mailing list
[email protected]
http://twistedmatrix.com/cgi-bin/mailman/listinfo/twisted-python

--===============3734921720336672141==--