﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
17354	Use system CA Certificates in Python3	ken@…	ken@…	"When Python is installed in LFS, we install pip3 as part of that, and various other modules are installed by pip3 in site-packages/pip/_vendor/. One of those modules in Certifi. For current 3.11.0 that is Certifi-2022-09-24 with the mozilla certs which were current when it was packaged, and those will not be updated unless, or until, pip or python3 are updated.

It is good practice for the System Administrator to control which certificates are used (in the same way that in perl modules, when building individually from source, we prefer the system certificates rather than a (probably very old) copy of Mozilla::CA).

Unfortunately, in LFS itself we cannot do that. But once make-ca and p11-kit have been installed, and make-ca has been configured, we can modify the relevant file.

I have a patch, Python-3.11.0-use_system_certs-1.patch, which I will be uploading. This is based on fedora from earlier this month.

It might probably need to be recreated at some point when the vendored copy of Certifi changes, so here I'm recording how it looks:

{{{
""""""
certifi.py
~~~~~~~~~~

This module returns the installation location of cacert.pem or its contents.
""""""

# Always use the system certificates
def where() -> str:
    return '/etc/pki/tls/certs/ca-bundle.crt'

def contents() -> str:
    with open(where(), encoding='utf=8') as data:
        return data.read()
}}}
 "	enhancement	closed	normal	11.3	BOOK	git	medium	fixed		
