Allow AWS-LC/BoringSSL error strings in TestIOStreamCheckHostname - #3705
Open
stewartsmith wants to merge 1 commit into
Open
Allow AWS-LC/BoringSSL error strings in TestIOStreamCheckHostname#3705stewartsmith wants to merge 1 commit into
stewartsmith wants to merge 1 commit into
Conversation
AWS-LC (and BoringSSL) report the uppercase name of the error reason where OpenSSL emits lowercase prose, so test_no_match failed with "did not get expected log message" when Python is linked against AWS-LC: [SSL: CERTIFICATE_VERIFY_FAILED] CERTIFICATE_VERIFY_FAILED: Hostname mismatch, certificate is not valid for 'bar.example.com'. [SSL: SSLV3_ALERT_BAD_CERTIFICATE] SSLV3_ALERT_BAD_CERTIFICATE Accept either spelling, following the same approach as CPython's python/cpython#116334.
Member
|
Looks good to me, although I don't want to get into a test matrix for all the possible SSL libraries out there. Is this implemented as a SSLCertVerificationError in all SSL implementations? Maybe we should be logging the type of the exception and then we can match on that in this assertion. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
AWS-LC (and BoringSSL) report the uppercase name of the error reason where OpenSSL emits lowercase prose, so test_no_match failed with "did not get expected log message" when Python is linked against AWS-LC:
[SSL: CERTIFICATE_VERIFY_FAILED] CERTIFICATE_VERIFY_FAILED: Hostname
mismatch, certificate is not valid for 'bar.example.com'.
[SSL: SSLV3_ALERT_BAD_CERTIFICATE] SSLV3_ALERT_BAD_CERTIFICATE
Accept either spelling, following the same approach as CPython's python/cpython#116334.