• Christian Heimes's avatar
    bpo-31432: Clarify ssl CERT_NONE/OPTIONAL/REQUIRED docs. (GH-3530) · ef24b6c5
    Christian Heimes authored
    The documentation for CERT_NONE, CERT_OPTIONAL, and CERT_REQUIRED were
    misleading and partly wrong. It fails to explain that OpenSSL behaves
    differently in client and server mode. Also OpenSSL does validate the
    cert chain everytime. With SSL_VERIFY_NONE a validation error is not
    fatal in client mode and does not request a client cert in server mode.
    Also discourage people from using CERT_OPTIONAL in client mode.
    ef24b6c5
2017-09-13-07-14-59.bpo-31432.yAY4Z3.rst 101 Bytes