From: R David Murray Date: Sun, 9 Mar 2014 23:41:25 +0000 (-0400) Subject: whatsnew: SSLContext.load_default_certs (#19292). X-Git-Tag: v3.4.1rc1~233^2~96 X-Git-Url: https://granicus.if.org/sourcecode?a=commitdiff_plain;h=01e6accd19695714924cdb846290682dcd86db6b;p=python whatsnew: SSLContext.load_default_certs (#19292). --- diff --git a/Doc/whatsnew/3.4.rst b/Doc/whatsnew/3.4.rst index 8861d88400..2d61cda51d 100644 --- a/Doc/whatsnew/3.4.rst +++ b/Doc/whatsnew/3.4.rst @@ -1318,6 +1318,15 @@ constants :data:`~ssl.VERIFY_DEFAULT`, :data:`~ssl.VERIFY_CRL_CHECK_LEAF`, OpenSSL does not do any CRL verification by default. (Contributed by Christien Heimes in :issue:`8813`.) +New :class:`~ssl.SSLContext` method :meth:`~ssl.SSLContext.load_default_certs` +loads a set of dfault "certificate authority" (CA) certificates from default +locations, which vary according to the platform. It can be used to load both +TLS web server authentication certificates +(``purpose=``:data:`~ssl.Purpose.SERVER_AUTH`) for a client to use to verify a +server, and certificates for a server to use in verifying client certificates +(``purpose=``:data:`~ssl.Purpose.CLIENT_AUTH`). (Contributed by Christian +Heimes in :issue:`19292`.) + stat ----