@@ -512,10 +512,11 @@ def fail(cert, hostname):
512512 fail (cert , 'Xa.com' )
513513 fail (cert , '.a.com' )
514514
515- # only match one left-most wildcard
515+ # only match wildcards when they are the only thing
516+ # in left-most segment
516517 cert = {'subject' : ((('commonName' , 'f*.com' ),),)}
517- ok (cert , 'foo.com' )
518- ok (cert , 'f.com' )
518+ fail (cert , 'foo.com' )
519+ fail (cert , 'f.com' )
519520 fail (cert , 'bar.com' )
520521 fail (cert , 'foo.a.com' )
521522 fail (cert , 'bar.foo.com' )
@@ -552,8 +553,8 @@ def fail(cert, hostname):
552553 # are supported.
553554 idna = 'www*.pythön.org' .encode ("idna" ).decode ("ascii" )
554555 cert = {'subject' : ((('commonName' , idna ),),)}
555- ok (cert , 'www.pythön.org' .encode ("idna" ).decode ("ascii" ))
556- ok (cert , 'www1.pythön.org' .encode ("idna" ).decode ("ascii" ))
556+ fail (cert , 'www.pythön.org' .encode ("idna" ).decode ("ascii" ))
557+ fail (cert , 'www1.pythön.org' .encode ("idna" ).decode ("ascii" ))
557558 fail (cert , 'ftp.pythön.org' .encode ("idna" ).decode ("ascii" ))
558559 fail (cert , 'pythön.org' .encode ("idna" ).decode ("ascii" ))
559560
@@ -637,7 +638,7 @@ def fail(cert, hostname):
637638 # Issue #17980: avoid denials of service by refusing more than one
638639 # wildcard per fragment.
639640 cert = {'subject' : ((('commonName' , 'a*b.com' ),),)}
640- ok (cert , 'axxb.com' )
641+ fail (cert , 'axxb.com' )
641642 cert = {'subject' : ((('commonName' , 'a*b.co*' ),),)}
642643 fail (cert , 'axxb.com' )
643644 cert = {'subject' : ((('commonName' , 'a*b*.com' ),),)}
0 commit comments