[Freeipa-devel] [PATCH 16/16] use NSS for SSL operations

John Dennis jdennis at redhat.com
Mon Jun 14 18:35:23 UTC 2010


This patch removes the use of OpenSSL (via Python's native libraries) 
for SSL operations and substitutes NSS for SSL. We were already using 
NSS in some places, now it's consistently universal.

Be aware that this patch depends on a an upgrade of python-nss to 0.9.

The patch also fixes a problem with certification validation, previously 
we had not been fully validating a certificate and as such it was a 
security vulnerability.

-- 
John Dennis <jdennis at redhat.com>

Looking to carve out IT costs?
www.redhat.com/carveoutcosts/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0016-use-NSS-for-SSL-operations.patch
Type: text/x-patch
Size: 28109 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20100614/6f046c1b/attachment.bin>


More information about the Freeipa-devel mailing list