diff options
| author | Guido van Rossum <guido@python.org> | 2013-10-16 08:35:41 -0700 |
|---|---|---|
| committer | Guido van Rossum <guido@python.org> | 2013-10-16 08:35:41 -0700 |
| commit | bd3bc95e034e54bd74ff7d28ade1830b1f03d6d5 (patch) | |
| tree | b148511e5e0a22ec656bcbf54aaa729e73b084c3 | |
| parent | e38367b1a0e36a83bc0f0ce61a7e4641d8b62a10 (diff) | |
| download | trollius-git-bd3bc95e034e54bd74ff7d28ade1830b1f03d6d5.tar.gz | |
Add OP_NO_SSLv2 to default SSLContext options.
| -rw-r--r-- | tulip/selector_events.py | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/tulip/selector_events.py b/tulip/selector_events.py index 40d7068..548c504 100644 --- a/tulip/selector_events.py +++ b/tulip/selector_events.py @@ -517,7 +517,10 @@ class _SelectorSslTransport(_SelectorTransport): sslcontext, ssl.SSLContext), 'Must pass an SSLContext' else: # Client-side may pass ssl=True to use a default context. - sslcontext = sslcontext or ssl.SSLContext(ssl.PROTOCOL_SSLv23) + # The default is the same as used by urllib. + if sslcontext is None: + sslcontext = ssl.SSLContext(ssl.PROTOCOL_SSLv23) + sslcontext.options |= ssl.OP_NO_SSLv2 wrap_kwargs = { 'server_side': server_side, 'do_handshake_on_connect': False, |
