[Bug 1815439] Re: python-boto needs to support SNI for OpenSSL 1.1.1
Bug Watch Updater
1815439 at bugs.launchpad.net
Mon Feb 11 11:36:53 UTC 2019
** Changed in: python-boto (Debian)
Status: Unknown => Fix Released
--
You received this bug notification because you are a member of Ubuntu
OpenStack, which is subscribed to python-boto in Ubuntu.
https://bugs.launchpad.net/bugs/1815439
Title:
python-boto needs to support SNI for OpenSSL 1.1.1
Status in python-boto package in Ubuntu:
Fix Released
Status in python-boto source package in Bionic:
In Progress
Status in python-boto source package in Cosmic:
In Progress
Status in python-boto package in Debian:
Fix Released
Bug description:
[Impact]
* OpenSSL 1.1.1 performs SNI hostname verification, therefore
hostname SSL context option must be set when establishing the
connection, otherwise, validation of SNI certificates fail and thus
resulting in lack of connectivity.
[Test Case]
* use python-boto to connect to an SNI tls protected host
[Regression Potential]
* change is compatible with pythons/openssl versions shipped in bionic/cosmic-release
* change is from upstream / tested in debian & disco
* change improves security, and is compatible with deployed servers out there
* hosts with certificates not matching their actual hostname will remain invalid/untrusted
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/python-boto/+bug/1815439/+subscriptions
More information about the Ubuntu-openstack-bugs
mailing list