NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #217 most downloaded on PyPI
Fast ASN.1 parser and serializer with definitions for private keys, public keys, certificates, CRL, OCSP, CMS, PKCS#3, PKCS#7, PKCS#8, PKCS#12, PKCS#5, X.509 and TSP
Last release 5 years ago
no release in 18 months
Ships unpredictably
gaps range from 9 days to 1.8 years
Nearly every release is documented
notes for 33 of 33 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
33 releases · first in 2015
Handle RSASSA-PSS in keys.PrivateKeyInfo.bit_size and keys.PublicKeyInfo.bit_size
keys.PrivateKeyInfo.bit_size and
keys.PublicKeyInfo.bit_sizekeys.PrivateKeyInfo.wrap and
keys.PublicKeyInfo.wrapkeys.PrivateKeyInfo.algorithm and
keys.PublicKeyInfo.algorithm to reflect that they can return
"rsassa_pss"Fix tsp.TimeStampAndCRL to be a core.Sequence instead of a core.SequenceOf *via @joernheissler*
tsp.TimeStampAndCRL to be a core.Sequence instead of a
core.SequenceOf via @joernheissleralgos.EncryptionAlgorithm when the
algorithm is RC2 via @joernheisslermicrosoft_enrollment_csp_provider
(1.3.6.1.4.1.311.13.2.2), microsoft_os_version
(1.3.6.1.4.1.311.13.2.3) and microsoft_request_client_info
(1.3.6.1.4.1.311.21.20)
to csr.CSRAttributeType along with supporting extension structures
via @qhamicrosoft_enroll_certtype (1.3.6.1.4.1.311.20.2)
to x509.ExtensionId via @qhacms.RoleSyntax, cms.SecurityCategory and cms.AttCertIssuer to
have explicit instead of implicit tagging via @MatthiasValvekenscms.Clearance via
@MatthiasValvekens.dump(force=True) when the value has undefined/unknown
core.Sequence fields. Previously the value would be truncated, now
the existing encoding is preserved.1.2.840.113549.1.9.15) support from RFC 2633
to cms.CMSAttribute via HellzedOne column per quarter.
core.ObjectIdentifier and all derived classes now obey X.660 §7.6 and thus restrict the first arc to 0 to 2, and the second arc to less than 40 if the
core.ObjectIdentifier and all derived classes now obey X.660 §7.6 and
thus restrict the first arc to 0 to 2, and the second arc to less than
40 if the first arc is 0 or 1. This also fixes parsing of OIDs where the
first arc is 2 and the second arc is greater than 39.keys.PublicKeyInfo.bit_size to return an int rather than a float
on Python 3 when working with elliptic curve keysasn1crypto-tests sdist on PyPi to work properly to generate a
.whlAdded encrypt_key_pref (1.2.840.113549.1.9.16.2.11) to cms.CMSAttributeType(), along with related structures
encrypt_key_pref (1.2.840.113549.1.9.16.2.11) to
cms.CMSAttributeType(), along with related structureskeys.NamedCurve()x509.Certificate().subject_directory_attributes_valuekeys.NamedCurve()TypeError when trying to call .untag() or .copy() on a
core.UTCTime() or core.GeneralizedTime(), or a value containing one,
when using Python 2Added asn1crypto.load_order(), which returns a list of unicode strings of the names of the fully-qualified module names for all of submodules of the p
asn1crypto.load_order(), which returns a list of unicode strings
of the names of the fully-qualified module names for all of submodules of
the package. The module names are listed in their dependency load order.
This is primarily intended for the sake of implementing hot reloading.Added User ID (0.9.2342.19200300.100.1.1) to x509.NameType()
0.9.2342.19200300.100.1.1) to x509.NameType()keys.NamedCurve()Fix an absolute import in keys to a relative import
keys to a relative importcms.KeyEncryptionAlgorithmId().native now returns the value "rsaes_pkcs1v15" for OID 1.2.840.113549.1.1.1 instead of "rsa"
cms.KeyEncryptionAlgorithmId().native now returns the value
"rsaes_pkcs1v15" for OID 1.2.840.113549.1.1.1 instead of "rsa"keys.PrivateKeyInfo().unwrap() is now
oscrypto.asymmetric.PrivateKey().unwrap()keys.PrivateKeyInfo().public_key is now
oscrypto.asymmetric.PrivateKey().public_key.unwrap()keys.PrivateKeyInfo().public_key_info is now
oscrypto.asymmetric.PrivateKey().public_key.asn1keys.PrivateKeyInfo().fingerprint is now
oscrypto.asymmetric.PrivateKey().fingerprintkeys.PublicKeyInfo().unwrap() is now
oscrypto.asymmetric.PublicKey().unwrap()keys.PublicKeyInfo().fingerprint is now
oscrypto.asymmetric.PublicKey().fingerprintcore.UTCTime() and
core.GeneralizedTime() values that include timezones and fractional
secondsutil.timezone has a more complete implementationcore.Choice() may now be constructed by a 2-element tuple or a 1-key
dictx509.Certificate().not_valid_before and
x509.Certificate().not_valid_aftercore.BitString().unused_bitskeys.NamedCurve.register() for non-mainstream curve OIDslibcrypto,
on Mac or Linuxocsp.CertStatus().native will now return meaningful unicode string
values when the status choice is "good" or "unknown". Previously
both returned None due to the way the structure was designed.1.2.840.113549.1.1.10) to
keys.PublicKeyInfo() and keys.PrivateKeyInfo()cms.CMSAttribute()1.2.840.113549.3.4) to algos.EncryptionAlgorithmId()1.3.132.0.10) to keys.NamedCurve()algos.DigestAlgorithmId() and
algos.HmacAlgorithmId()1.2.840.113549.1.1.7) to
cms.KeyEncryptionAlgorithmId()1.3.6.1.5.5.8.2.2) to x509.KeyPurposeId()x509.EmailAddress() and x509.DNSName() now handle invalidly-encoded
values using tags for core.PrintableString() and core.UTF8String()algos.EncryptionAlgorithm()core.Sequence() and
core.SequenceOf() valuescore.IntegerBitString() and core.IntegerOctetString() now restrict
values to non-negative integers since negative values are not
implemented.dump(True) must be called.UnboundLocalError when calling x509.IPAddress().native on an
encoded value that has a length of zeroclass_ via unicode string name to core.Asn1Value()keys.ECPrivateKey() more narrowly than RFC 5915 requiresutil.int_to_bytes()x509.URI() now only normalizes values when comparingcore.BitString()core.BitString()core.Choice().parse()core.Choice().contents working when the chosen alternative is a
core.Choice() alsocore.Choice() objectscore.ObjectIdentifier().native to sometimes not
map the OIDwheel, sdist and bdist_egg releases now all include LICENSE,
sdist includes docsasn1crypto_tests package to PyPix509.Certificate().self_signed will no longer return "yes" under any circumstances. This helps prevent confusion since the library does not verify the
x509.Certificate().self_signed will no longer return "yes" under any
circumstances. This helps prevent confusion since the library does not
verify the signature. Instead a library like oscrypto should be used
to confirm if a certificate is self-signed.x509.KeyPurposeId()x509.Certificate().private_key_usage_period_valuex509.SubjectDirectoryAttribute()algos.AnyAlgorithmIdentifier() for situations where an
algorithm identifier may contain a digest, signed digest or encryption
algorithm OIDx509.Certificate().subject_directory_attributes_value
not returning the correct valuecore.Sequence() would
not function properly when the field had a default valuepem.armor()Backwards compatibility break: the tag_type, explicit_tag and explicit_class attributes on core.Asn1Value no longer exist and were replaced by the imp
tag_type, explicit_tag and
explicit_class attributes on core.Asn1Value no longer exist and were
replaced by the implicit and explicit attributes. Field param dicts
may use the new explicit and implicit keys, or the old tag_type and
tag keys. The attribute changes will likely to have little to no impact
since they were primarily an implementation detail.x509.strict_teletex() context manager.UnicodeDecodeError when trying to find the (optional) dependency
OpenSSL on Python 2next_update field of crl.TbsCertList to be optionalx509.Certificate.sha256_fingerprint propertyx509.Certificate.ocsp_urls and x509.DistributionPoint.url will now
return https://, ldap:// and ldaps:// URLs in addition to http://.Implemented proper support for BER-encoded indefinite length strings of all kinds - core.BitString, core.OctetString and all of the core classes that
parser.peek()core.BitString, core.OctetString and all of the core
classes that are natively represented as Python unicode stringsx509.URIx509.DNSName to allow a leading ., such as when used with
x509.NameConstraintscore.Any when
explicitly taggedsetup.py clean now accepts the short -a flag for compatibilityFixed a regression where explicit tagging of a field containing a core.Choice would result in an incorrect header
core.Choice would result in an incorrect headerIndexError was being raised instead of a ValueError
when a value was truncated to not include enough bytes for the headervalue field of pkcs12.Attribute2.16.840.1.113894.746875.1.1 OID to
pkcs12.AttributeTypeAdded core.load() for loading standard, universal types without knowing the spec beforehand
core.load() for loading standard, universal types without knowing
the spec beforehandstrict keyword arg to the various load() methods and functions in
core that checks for trailing data and raises a ValueError when foundasn1crypto.parser submodule with emit() and parse() functions for
low-level integrationasn1crypto.version for version introspection without side-effectsalgos.DSASignature_header attribute of explicitly-tagged values only
containing the explicit tag header instead of both the explicit tag header
and the encapsulated value headerAdded the OID for unique identifier to x509.NameType
x509.NameTypecore.BitString with
leading null bytes.cast() method to allow converting between different
representations of the same data, e.g. core.BitString and
core.OctetBitStringForce algos.DigestAlgorithm to encoding parameters as Null when the algorithm is sha1, sha224, sha256, sha384 or sha512 per RFC 4055
algos.DigestAlgorithm to encoding parameters as Null when the
algorithm is sha1, sha224, sha256, sha384 or sha512 per RFC 4055core.Sequence or core.Setx509.Name.build() to properly handle dotted OID type valuescore.Choice can now be constructed from a single-element dict or a
two-element tuple to allow for better usability when constructing values
from native Python valuescore objects can now be passed to print() with an exception being
raisedDon't fail importing if ctypes or _ctypes is not available
ctypes or _ctypes is not availablecore.Sequence will now raise an exception when an unknown field is provided
core.Sequence will now raise an exception when an unknown field is providedUnicodeDecodeError on Python 2 when calling
core.OctetString.debug()hash_algorithm field of
tsp.ESSCertIDv2cms.SignedData objectparameters set to
core.NullFixed DER encoding of core.BitString when a _map is specified (i.e. a "named bit list") to omit trailing zero bits. This fixes compliance of various x
core.BitString when a _map is specified (i.e. a
"named bit list") to omit trailing zero bits. This fixes compliance of
various x509 structures with RFC 5280.keys.PrivateKeyInfo.wrap() that would cause the
original keys.ECPrivateKey structure to become corruptcore.IntegerOctetString now correctly encodes the integer as an unsigned
value when converting to bytes. Previously decoding was unsigned, but
encoding was signed.util.int_from_bytes() on Python 2 to return 0 from an empty byte
stringAllow _perf submodule to be removed from source tree when embedding
_perf submodule to be removed from source tree when embeddingFixed DER encoding of core.Set and core.SetOf
core.Set and core.SetOfx509.Name.build() that could generate invalid DER encoding.native
attributealgos.SignedDigestAlgorithm now ensures the parameters are set to
Null when algorithm is sha224_rsa, sha256_rsa, sha384_rsa or
sha512_rsa, per RFC 4055pdf.AdobeTimestamp to mark the
requires_auth field as optional1.2.840.113549.1.9.16.2.14 to
cms.CMSAttributeTypecms.AttributeCertificateV2cms.AttributeCertificateV2 when incorrectly tagged as
cms.AttributeCertificateV1 in cms.CertificateChoicesImproved general parsing performance by 10-15%
core.ObjectIdentifier.dotted attribute to always return dotted
integer unicode stringcore.ObjectIdentifier.map() and core.ObjectIdentifier.unmap()
class methods to map dotted integer unicode strings to user-friendly unicode
strings and backx509.KeyPurposeIdx509.Certificate.issuer_alt_name_value if it is the first
extension queriedkeys.PublicKeyInfo.bit_size and keys.PrivateKeyInfo.bit_size values are
now rounded up to the next closest multiple of 8Fix a bug in x509.URI parsing IRIs containing explicit port numbers on Python 3.x
x509.URI parsing IRIs containing explicit port numbers on
Python 3.xAdded x509.TrustedCertificate for handling OpenSSL auxiliary certificate information appended after a certificate
x509.TrustedCertificate for handling OpenSSL auxiliary certificate
information appended after a certificatecore.Concat class for situations such as x509.TrustedCertificatecore.IA5String where an
x509.DirectoryString should be used insteadkeys.PrivateKeyInfo.public_key_info attributex509.KeyPurposeIdAdded DH key exchange structures: algos.KeyExchangeAlgorithm, algos.KeyExchangeAlgorithmId and algos.DHParameters.
algos.KeyExchangeAlgorithm,
algos.KeyExchangeAlgorithmId and algos.DHParameters.keys.PublicKeyInfo,
keys.PublicKeyAlgorithm and keys.PublicKeyAlgorithmId. New structures
include keys.DomainParameters and keys.ValidationParms.Fixed cms.CMSAttributes to be a core.SetOf instead of core.SequenceOf
cms.CMSAttributes to be a core.SetOf instead of core.SequenceOfcms.CMSAttribute can now parse unknown attribute contrustruct without an
exception being raisedx509.PolicyMapping now uses x509.PolicyIdentifier for field typespdf.RevocationInfoArchival so that all fields are now of the type
core.SequenceOf instead of a single valuename_distinguisher, telephone_number and
organization_identifier OIDs to x509.Namex509.Name.native to not accidentally create nested lists when three
of more values for a single type are part of the namex509.Name.human_friendly now reverses the order of fields when the data
in an x509.Name was encoded in most-specific to least-specific order, which
is the opposite of the standard way of least-specific to most-specific.x509.NameType.human_friendly no longer raises an exception when an
unknown OID is encounteredValueError when parsing a core.Set and an unknown field is
encounteredAdded support for the TLS feature extension from RFC 7633
x509.Name.build() now accepts a keyword parameter use_printable to force
string encoding to be core.PrintableString instead of core.UTF8Stringutil.uri_to_iri() and util.iri_to_uri()algos.SignedDigestAlgorithmId to use the preferred OIDs when
mapping a unicode string name to an OID. Previously there were multiple OIDs
for some algorithms, and different OIDs would sometimes be selected due to
the fact that the _map dict is not ordered.Fixed a bug generating x509.Certificate.sha1_fingerprint on Python 2
x509.Certificate.sha1_fingerprint on Python 2Added the x509.Certificate.sha1_fingerprint attribute
x509.Certificate.sha1_fingerprint attributeBackwards compatibility break: the native representation of some algos.EncryptionAlgorithmId values changed. aes128 became aes128_cbc, aes192 became a
algos.EncryptionAlgorithmId values changed. aes128 became aes128_cbc,
aes192 became aes192_cbc and aes256 became aes256_cbc.algos.EncryptionAlgorithmIdcms.KeyEncryptionAlgorithmIdx509.Name.human_friendly now properly supports multiple values per
x509.NameTypeAndValue objectocsp.OCSPResponse.basic_ocsp_response and
ocsp.OCSPResponse.response_data propertiesalgos.EncryptionAlgorithm.encryption_mode propertyattributes field of csr.CertificationRequestInfo is now optional,
for compatibility with other ASN.1 parsersCorrect core.Sequence.__setitem__() so set core.VOID to an optional field when None is set
core.Sequence.__setitem__() so set core.VOID to an optional
field when None is setFixed a unicode/bytes bug with x509.URI.dump() on Python 2
unicode/bytes bug with x509.URI.dump() on Python 2Backwards Compatibility Break: core.NoValue was renamed to core.Void and a singleton was added as core.VOID
core.NoValue was renamed to core.Void and
a singleton was added as core.VOIDcore.Void now implements __nonzero__core.Asn1Value.copy() now performs a deep copycore value classes are now compatible with the copy modulecore.SequenceOf and core.SetOf now implement __contains__x509.Name.__len__()core.Choice.validate() would not properly account for
explicit taggingcore.Choice.load() now properly passes itself as the spec when parsingx509.Certificate.crl_distribution_points no longer throws an exception if
the DistributionPoint does not have a value for the distribution_point
fieldCorrected core.UTCTime to interpret year <= 49 as 20xx and >= 50 as 19xx
core.UTCTime to interpret year <= 49 as 20xx and >= 50 as 19xxkeys.PublicKeyInfo.hash_algo can now handle DSA keys without parameterscrl.CertificateList.sha256 and crl.CertificateList.sha1x509.Name.build() to properly encode country_name, serial_number
and dn_qualifier as core.PrintableString as specified in RFC 5280,
instead of core.UTF8StringYour coding agent can read these notes before it upgrades. Set up the MCP server →