]> git.ipfire.org Git - thirdparty/Python/cpython.git/commitdiff
bpo-38815: Accept TLSv3 default in min max test (GH-NNNN) (GH-17437)
authorMiss Islington (bot) <31488909+miss-islington@users.noreply.github.com>
Mon, 2 Dec 2019 16:35:50 +0000 (08:35 -0800)
committerGitHub <noreply@github.com>
Mon, 2 Dec 2019 16:35:50 +0000 (08:35 -0800)
Make ssl tests less strict and also accept TLSv3 as the default maximum
version. This change unbreaks test_min_max_version on Fedora 32.

https://bugs.python.org/issue38815
(cherry picked from commit 34864d1cffdbfc620f8517dab9a68ae9a37b8c53)

Co-authored-by: torsava <torsava@redhat.com>
Lib/test/test_ssl.py

index e21e7e07455cccd2aa7b517bce1507e160d978d4..a01999f6aa3d8009e62fbbec4cbd57579b6f0aeb 100644 (file)
@@ -1220,12 +1220,18 @@ class ContextTests(unittest.TestCase):
             # RHEL 8 uses TLS 1.2 by default
             ssl.TLSVersion.TLSv1_2
         }
+        maximum_range = {
+            # stock OpenSSL
+            ssl.TLSVersion.MAXIMUM_SUPPORTED,
+            # Fedora 32 uses TLS 1.3 by default
+            ssl.TLSVersion.TLSv1_3
+        }
 
         self.assertIn(
             ctx.minimum_version, minimum_range
         )
-        self.assertEqual(
-            ctx.maximum_version, ssl.TLSVersion.MAXIMUM_SUPPORTED
+        self.assertIn(
+            ctx.maximum_version, maximum_range
         )
 
         ctx.minimum_version = ssl.TLSVersion.TLSv1_1