changeset: 100250:3cddcf471c70 branch: 2.7 parent: 100244:58ebfa7c1361 user: Benjamin Peterson date: Wed Feb 17 22:13:19 2016 -0800 files: Misc/NEWS Modules/_ssl.c description: open the cert store readonly Patch from Chi Hsuan Yen. diff -r 58ebfa7c1361 -r 3cddcf471c70 Misc/NEWS --- a/Misc/NEWS Mon Feb 15 16:51:24 2016 +1100 +++ b/Misc/NEWS Wed Feb 17 22:13:19 2016 -0800 @@ -50,6 +50,8 @@ Library ------- +- Issue #25939: On Windows open the cert store readonly in ssl.enum_certificates. + - Issue #24303: Fix random EEXIST upon multiprocessing semaphores creation with Linux PID namespaces enabled. diff -r 58ebfa7c1361 -r 3cddcf471c70 Modules/_ssl.c --- a/Modules/_ssl.c Mon Feb 15 16:51:24 2016 +1100 +++ b/Modules/_ssl.c Wed Feb 17 22:13:19 2016 -0800 @@ -3653,7 +3653,9 @@ if (result == NULL) { return NULL; } - hStore = CertOpenSystemStore((HCRYPTPROV)NULL, store_name); + hStore = CertOpenStore(CERT_STORE_PROV_SYSTEM_A, 0, (HCRYPTPROV)NULL, + CERT_STORE_READONLY_FLAG | CERT_SYSTEM_STORE_LOCAL_MACHINE, + store_name); if (hStore == NULL) { Py_DECREF(result); return PyErr_SetFromWindowsErr(GetLastError()); @@ -3741,7 +3743,9 @@ if (result == NULL) { return NULL; } - hStore = CertOpenSystemStore((HCRYPTPROV)NULL, store_name); + hStore = CertOpenStore(CERT_STORE_PROV_SYSTEM_A, 0, (HCRYPTPROV)NULL, + CERT_STORE_READONLY_FLAG | CERT_SYSTEM_STORE_LOCAL_MACHINE, + store_name); if (hStore == NULL) { Py_DECREF(result); return PyErr_SetFromWindowsErr(GetLastError());