# Python 3.13.x SSL security changes

**URL:** <https://discuss.python.org/t/python-3-13-x-ssl-security-changes/91266>\
**Category:** Python Help\
**Tags:** security\
**Created:** [May 8, 2025, 5:10pm UTC](https://discuss.python.org/t/python-3-13-x-ssl-security-changes/91266 "2025-05-08T17:10:33Z")\
**Posts on this page:** 1\
**Showing post:** 9

<div class="post-metadata">

**Author:** ![meiswjn](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/meiswjn/32/28569_2.png) [@meiswjn](https://discuss.python.org/u/meiswjn)\
**Post date:** [June 12, 2025, 12:49pm UTC](https://discuss.python.org/t/python-3-13-x-ssl-security-changes/91266/9 "2025-06-12T12:49:12Z")

</div>

I think I found the issue and understand why the steps you followed solved the issue.

In your first post, you only reference the root certificate for validation. Later, after you followed the guide and exported the certificates via chrome, you reference both the root certificate AND the intermediate certificate. In the intermediate certificate, the attribute X509v3 Basic Constraints is actually set to “critical”, in root it is not.

From [RFC 5280: Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile](https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.9:)

> Conforming CAs MUST include this extension in all CA certificates  
> that contain public keys used to validate digital signatures on  
> certificates and MUST mark the extension as critical in such  
> certificates.

So yes, **the solution is to also include the intermediate certificate** (s) in your trust chain, atleast for the current ZScaler certificates, as the intermediate cert has the correct attribute. I recommend to only include the first intermediate certificate along with the root cert, as it has a long validity in contrast to the second intermediate cert, which is only valid for ~2 weeks.

Here is how you can validate it yourself:

```python
openssl x509 -text -noout -in zscaler_root.crt

```

```python
...
 X509v3 Basic Constraints: 
     CA:TRUE
...

```

```python
openssl x509 -text -noout -in zscaler_first_intermediate.crt

```

```python
...
X509v3 Basic Constraints: critical
    CA:TRUE
...

```

And in Python:

```python
>>> requests.get(some_url, verify="only_intermediate_1.crt")
<Response [200]>
>>> requests.get(some_url, verify="only_root.crt")
<ssl basic constraint not critical error>

```

Here is also the discussion where it was introduced in Python 3.13: [`ssl`: changing the default `SSLContext.verify_flags`? - #15 by gpshead](https://discuss.python.org/t/ssl-changing-the-default-sslcontext-verify-flags/30230/15)

---

_[View the full topic](https://discuss.python.org/t/python-3-13-x-ssl-security-changes/91266)._
