[Openstack-security] [Bug 1201534] Re: heat.common.urlfetch does not validate server SSL certificates

Thierry Carrez thierry.carrez+lp at gmail.com
Thu Sep 5 10:06:28 UTC 2013


** Changed in: heat
       Status: Fix Committed => Fix Released

** Changed in: heat
    Milestone: None => havana-3

-- 
You received this bug notification because you are a member of OpenStack
Security Group, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1201534

Title:
  heat.common.urlfetch does not validate server SSL certificates

Status in Orchestration API (Heat):
  Fix Released

Bug description:
  urllib2 is not considered "safe" for SSL communications. It does
  nothing to validate the server SSL certificate.

  We should migrate to requests, which has become common in OpenStack.

To manage notifications about this bug go to:
https://bugs.launchpad.net/heat/+bug/1201534/+subscriptions




More information about the Openstack-security mailing list