e2c2602
Author: Jamie Strandboge <jamie@canonical.com>
e2c2602
Description: require SSL certificate validation by default by using
e2c2602
 CERT_REQUIRED and using the system /etc/ssl/certs/ca-certificates.crt
e2c2602
Bug-Ubuntu: https://launchpad.net/bugs/1047054
e2c2602
Modified for Fedora by Ralph Bean <rbean@redhat.com>
e2c2602
Bug-Fedora: https://bugzilla.redhat.com/show_bug.cgi?id=855320
e2c2602
e2c2602
Index: urllib3-1.5/urllib3/connectionpool.py
e2c2602
===================================================================
e2c2602
--- urllib3-1.5.orig/urllib3/connectionpool.py
e2c2602
+++ urllib3-1.5/urllib3/connectionpool.py
e2c2602
@@ -504,7 +504,7 @@ class HTTPSConnectionPool(HTTPConnection
e2c2602
                  strict=False, timeout=None, maxsize=1,
e2c2602
                  block=False, headers=None,
e2c2602
                  key_file=None, cert_file=None,
e2c2602
-                 cert_reqs='CERT_NONE', ca_certs=None):
e2c2602
+                 cert_reqs='CERT_REQUIRED', ca_certs='/etc/ssl/certs/ca-certificates.crt'):
e2c2602
 
e2c2602
         super(HTTPSConnectionPool, self).__init__(host, port,
e2c2602
                                                   strict, timeout, maxsize,