changeset: 100252:8ff4c1827499 branch: 3.5 parent: 100248:8ee91cb2e2a4 parent: 100251:9f29cf9ad17f user: Benjamin Peterson date: Wed Feb 17 22:18:20 2016 -0800 files: Misc/NEWS Modules/_ssl.c Modules/clinic/_ssl.c.h description: merge 3.4 (closes #25939) diff -r 8ee91cb2e2a4 -r 8ff4c1827499 Misc/NEWS --- a/Misc/NEWS Tue Feb 16 13:27:04 2016 +1100 +++ b/Misc/NEWS Wed Feb 17 22:18:20 2016 -0800 @@ -76,6 +76,8 @@ Library ------- +- Issue #25939: On Windows open the cert store readonly in ssl.enum_certificates. + - Issue #25995: os.walk() no longer uses FDs proportional to the tree depth. - Issue #26117: The os.scandir() iterator now closes file descriptor not only diff -r 8ee91cb2e2a4 -r 8ff4c1827499 Modules/_ssl.c --- a/Modules/_ssl.c Tue Feb 16 13:27:04 2016 +1100 +++ b/Modules/_ssl.c Wed Feb 17 22:18:20 2016 -0800 @@ -4198,7 +4198,9 @@ if (result == NULL) { return NULL; } - hStore = CertOpenSystemStore((HCRYPTPROV)NULL, store_name); + hStore = CertOpenStore(CERT_STORE_PROV_SYSTEM_A, 0, (HCRYPTPROV)NULL, + CERT_STORE_READONLY_FLAG | CERT_SYSTEM_STORE_LOCAL_MACHINE, + store_name); if (hStore == NULL) { Py_DECREF(result); return PyErr_SetFromWindowsErr(GetLastError()); @@ -4284,7 +4286,9 @@ if (result == NULL) { return NULL; } - hStore = CertOpenSystemStore((HCRYPTPROV)NULL, store_name); + hStore = CertOpenStore(CERT_STORE_PROV_SYSTEM_A, 0, (HCRYPTPROV)NULL, + CERT_STORE_READONLY_FLAG | CERT_SYSTEM_STORE_LOCAL_MACHINE, + store_name); if (hStore == NULL) { Py_DECREF(result); return PyErr_SetFromWindowsErr(GetLastError());