Skip to content

Allow AWS-LC/BoringSSL error strings in TestIOStreamCheckHostname - #3705

Open
stewartsmith wants to merge 1 commit into
tornadoweb:masterfrom
stewartsmith:aws-lc-error-strings
Open

Allow AWS-LC/BoringSSL error strings in TestIOStreamCheckHostname#3705
stewartsmith wants to merge 1 commit into
tornadoweb:masterfrom
stewartsmith:aws-lc-error-strings

Conversation

@stewartsmith

Copy link
Copy Markdown

AWS-LC (and BoringSSL) report the uppercase name of the error reason where OpenSSL emits lowercase prose, so test_no_match failed with "did not get expected log message" when Python is linked against AWS-LC:

[SSL: CERTIFICATE_VERIFY_FAILED] CERTIFICATE_VERIFY_FAILED: Hostname
mismatch, certificate is not valid for 'bar.example.com'.
[SSL: SSLV3_ALERT_BAD_CERTIFICATE] SSLV3_ALERT_BAD_CERTIFICATE

Accept either spelling, following the same approach as CPython's python/cpython#116334.

AWS-LC (and BoringSSL) report the uppercase name of the error reason
where OpenSSL emits lowercase prose, so test_no_match failed with
"did not get expected log message" when Python is linked against
AWS-LC:

  [SSL: CERTIFICATE_VERIFY_FAILED] CERTIFICATE_VERIFY_FAILED: Hostname
  mismatch, certificate is not valid for 'bar.example.com'.
  [SSL: SSLV3_ALERT_BAD_CERTIFICATE] SSLV3_ALERT_BAD_CERTIFICATE

Accept either spelling, following the same approach as CPython's
python/cpython#116334.
@bdarnell

bdarnell commented Aug 7, 2026

Copy link
Copy Markdown
Member

Looks good to me, although I don't want to get into a test matrix for all the possible SSL libraries out there.

Is this implemented as a SSLCertVerificationError in all SSL implementations? Maybe we should be logging the type of the exception and then we can match on that in this assertion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants