Using ssl.wrap_socket() in chroot jail

Chris Angelico rosuav at gmail.com
Wed May 7 22:12:08 EDT 2014


On Thu, May 8, 2014 at 4:51 AM, Grant Edwards <invalid at invalid.invalid> wrote:
> Unfortunately, the actual SSL wrapping stuff isn't being done in my
> code.  It's being done by the secure-smtpd module, which will pass
> whatever cert/key params I give it to ssl.wrap_socket().  That still
> leaves the third option (e.g. stunnel).

I'll go back to the naughty-crazy idea of monkey-patching, then: can
you create an SSLContext prior to chrooting, then stuff its
wrap_socket back into the ssl module?

ChrisA



More information about the Python-list mailing list