gwibber-bugs team mailing list archive
-
gwibber-bugs team
-
Mailing list archive
-
Message #01096
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
meh, we could wrap each and every urllib2.urlopen call with something like this:
http://stackoverflow.com/questions/1087227/validate-ssl-certificates-with-python/3551700#3551700
But I'd like to hear something from Ryan before patching :)
--
You received this bug notification because you are a member of Gwibber
Bug Heros, which is subscribed to Gwibber.
https://bugs.launchpad.net/bugs/705363
Title:
gwibber bypasses certificate checking when providing the
login/password for OAuth
Status in Gwibber:
New
Status in “gwibber” package in Debian:
Confirmed
Bug description:
Someone reported this in Debian: http://bugs.debian.org/cgi-
bin/bugreport.cgi?bug=608724
identi.ca had (mistakenly) installed an SSL certificate not recognized
by the installed CA, yet the user has been presented with the OAuth
login screen even if that https connection could not be authentified.
To manage notifications about this bug go to:
https://bugs.launchpad.net/gwibber/+bug/705363/+subscriptions
References