[Openstack-security] [Bug 1201534] Re: heat.common.urlfetch does not validate server SSL certificates

OpenStack Hudson 1201534 at bugs.launchpad.net
Wed Jul 24 02:10:04 UTC 2013


Fix proposed to branch: master
Review: https://review.openstack.org/38403

** Changed in: heat
       Status: Triaged => In Progress

** Changed in: heat
     Assignee: (unassigned) => Davanum Srinivas (DIMS) (dims-v)

-- 
You received this bug notification because you are a member of OpenStack
Security Group, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1201534

Title:
  heat.common.urlfetch does not validate server SSL certificates

Status in Orchestration API (Heat):
  In Progress

Bug description:
  urllib2 is not considered "safe" for SSL communications. It does
  nothing to validate the server SSL certificate.

  We should migrate to requests, which has become common in OpenStack.

To manage notifications about this bug go to:
https://bugs.launchpad.net/heat/+bug/1201534/+subscriptions




More information about the Openstack-security mailing list