Re: SSL work is ready for review
Bill Janssen <[email protected]>
| Newsgroups | gmane.comp.web.zope.zodb |
|---|---|
| Message-ID | <[email protected]> |
I'll try to get to it over the weekend. Bill On Wednesday, June 29, 2016 at 11:01:58 AM UTC-7, Jim Fulton wrote: > > WRT the use case questions we were discussing: > > - Both clients and servers have to be authenticated > > - Clients can authenticate servers using self-signed server certs or > signed server certs + host name > > - Servers authenticate clients via specified CA (could be private CA > or just the client cert). (I expect us to provide other options > later.) > > - Host name checking is done by clients unless it's disabled > > WRT level of security, I decided to: > > - Rely on ssl.create_default_context(ssl.Purpose.CLIENT_AUTH) and > enabling certificate verification to get a secure base configuration > appropriate for the platform. > > - Added some verification flags suggested by Julien "We also enable > VERIFY_X509_STRICT and CRL check if there's one." > > - Always verify certificates > > Note that the Python APIs for creating clients and servers (the later > a bit complicated :/) take an SSLContext so if you have special needs > that we're not meeting, you can implement them yourself. (If you have > general needs we're not meeting, we're probably doing something wrong. > :) ) > > The pull request is here: > > https://github.com/zopefoundation/ZEO/pull/32 > > This is an initial cut. We can expand on this later if needed. > > This isn't a very big PR. I hope I can get some reviewers for this one. :) > > (The PR is a bit bigger than I'd hoped, because SSL on Linux forced me > to switch to a single-threaded server implementation.) > > Jim > > -- > Jim Fulton > http://jimfulton.info > -- You received this message because you are subscribed to the Google Groups "zodb" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.