NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #9 most downloaded on PyPI
cryptography is a package which provides cryptographic recipes and primitives to Python developers.
Last release 4 days ago
30 Sep 2026
Release timing varies
gaps range from 1 weeks to 3 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
3 versions withdrawn
withdrawn after publishing
13 years old
160 releases · first in 2014
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.3.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.3.
Added abi3.abi3t wheels for free-threaded CPython 3.15 and later.
Updated to PyO3 0.29.2, which fixes building cryptography on Cygwin and MSYS2.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.
One column per quarter.
A random key is now substituted on failure, as described in RFC 3218. Credit to @X1AOxiang for reporting the issue. CVE-2026-69247
SECURITY ISSUE: ~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a RecipientInfo's encryptedKey, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages. A random key is now substituted on failure, as described in 3218. Credit to @X1AOxiang for reporting the issue. CVE-2026-69247
Deprecated Diffie-Hellman key exchange over finite fields (FFDH). Everything FFDH is deprecated, including the types in cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or parameters with the key loading APIs. Users should migrate to a more modern key exchange algorithm.
Added xof() class methods to ~cryptography.hazmat.primitives.hashes.SHAKE128 and ~cryptography.hazmat.primitives.hashes.SHAKE256 for constructing algorithm instances configured for use with ~cryptography.hazmat.primitives.hashes.XOFHash.
The X.509 verification APIs are now considered stable and are subject to our API stability policy.
Added the /cobblestone recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification for streaming authenticated encryption of large messages.
Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT, instead of silently ignoring them.
Added support for using ~cryptography.x509.Name as a field type in the /hazmat/asn1/index module.
Loading a public key or an EC private key now rejects DER where the subjectPublicKey (or EC publicKey) BIT STRING declares a non-zero number of unused bits, instead of silently ignoring it.
Parsing a CRL entry's InvalidityDate extension now rejects a GeneralizedTime that carries fractional seconds or another non-DER form, matching the strict encoding already required for every other X.509 time field.
~cryptography.x509.ocsp.load_der_ocsp_request and ~cryptography.x509.ocsp.load_der_ocsp_response now reject a request or response whose version field is not v1, the only version defined by RFC 6960, matching the version validation already performed when loading certificates, CSRs and CRLs.
~cryptography.hazmat.primitives.hashes.XOFHash is now supported when building against AWS-LC.
HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when building against AWS-LC.
Diffie-Hellman (/hazmat/primitives/asymmetric/dh) is now supported when building against AWS-LC.
~cryptography.hazmat.primitives.serialization.load_der_public_key and ~cryptography.hazmat.primitives.serialization.load_pem_public_key now reject Diffie-Hellman public keys whose modulus is smaller than 512 bits, matching the minimum already enforced when loading DH private keys and when constructing ~cryptography.hazmat.primitives.asymmetric.dh.DHParameterNumbers.
Added ~cryptography.hazmat.primitives.asymmetric.mldsa.MLDSAMuHasher for incrementally computing the ML-DSA mu (message representative) used by the external-mu signing and verification APIs.
The builtin ~cryptography.hazmat.primitives.hashes.HashAlgorithm classes and the classes in ~cryptography.hazmat.primitives.asymmetric.padding can now be compared with ==.
~cryptography.x509.CertificateBuilder now supports creating unsigned certificates (9925) with the create_unsigned method.
The X.509 verification APIs now permit ML-DSA-44, ML-DSA-65, and ML-DSA-87 (9881) public keys and signatures by default.
SECURITY ISSUE : pkcs7_decrypt_der() and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a RecipientInfo ’s encryptedKey , which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages. A random key is now substituted on failure, as described in RFC 3218 . Credit to @X1AOxiang for reporting the issue. CVE-2026-69247
Deprecated Diffie-Hellman key exchange over finite fields (FFDH). Everything FFDH is deprecated, including the types in cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or parameters with the key loading APIs. Users should migrate to a more modern key exchange algorithm.
Added xof() class methods to SHAKE128 and SHAKE256 for constructing algorithm instances configured for use with XOFHash .
The X.509 verification APIs are now considered stable and are subject to our API stability policy.
Added the Cobblestone (streaming symmetric encryption) recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification for streaming authenticated encryption of large messages.
Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT, instead of silently ignoring them.
Added support for using Name as a field type in the ASN.1 module.
Loading a public key or an EC private key now rejects DER where the subjectPublicKey (or EC publicKey ) BIT STRING declares a non-zero number of unused bits, instead of silently ignoring it.
Parsing a CRL entry’s InvalidityDate extension now rejects a GeneralizedTime that carries fractional seconds or another non-DER form, matching the strict encoding already required for every other X.509 time field.
load_der_ocsp_request() and load_der_ocsp_response() now reject a request or response whose version field is not v1 , the only version defined by RFC 6960, matching the version validation already performed when loading certificates, CSRs and CRLs.
XOFHash is now supported when building against AWS-LC.
HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when building against AWS-LC.
Diffie-Hellman ( Diffie-Hellman key exchange ) is now supported when building against AWS-LC.
load_der_public_key() and load_pem_public_key() now reject Diffie-Hellman public keys whose modulus is smaller than 512 bits, matching the minimum already enforced when loading DH private keys and when constructing DHParameterNumbers .
Added MLDSAMuHasher for incrementally computing the ML-DSA mu (message representative) used by the external-mu signing and verification APIs.
The builtin HashAlgorithm classes and the classes in padding can now be compared with == .
CertificateBuilder now supports creating unsigned certificates ( RFC 9925 ) with the create_unsigned method.
The X.509 verification APIs now permit ML-DSA-44, ML-DSA-65, and ML-DSA-87 ( RFC 9881 ) public keys and signatures by default.
BACKWARDS INCOMPATIBLE: Support for x86_64 macOS has been removed. We now only publish arm64 wheels for macOS.
BACKWARDS INCOMPATIBLE: Support for x86_64 macOS has been removed. We now only publish arm64 wheels for macOS.
BACKWARDS INCOMPATIBLE: Support for 32-bit Windows has been removed. Users should move to a 64-bit Python installation.
BACKWARDS INCOMPATIBLE: Removed the deprecated PUBLIC_KEY_TYPES, PRIVATE_KEY_TYPES, CERTIFICATE_PRIVATE_KEY_TYPES, CERTIFICATE_ISSUER_PUBLIC_KEY_TYPES, and CERTIFICATE_PUBLIC_KEY_TYPES type aliases. Use PublicKeyTypes, PrivateKeyTypes, CertificateIssuerPrivateKeyTypes, CertificateIssuerPublicKeyTypes, and CertificatePublicKeyTypes instead. These were deprecated in version 40.0.
BACKWARDS INCOMPATIBLE: ~cryptography.hazmat.primitives.ciphers.algorithms.ChaCha20 now treats the first 4 bytes of the nonce as a 32-bit little-endian block counter (as defined in 7539) and tracks the number of bytes processed. Attempting to encrypt or decrypt more data than the counter allows before it would overflow now raises a ValueError rather than silently diverging from RFC 7539. Setting the counter portion of the nonce to zero allows encrypting up to 256 GiB with a given nonce.
BACKWARDS INCOMPATIBLE: Loading an X.509 certificate whose ECDSA or DSA signature AlgorithmIdentifier contains encoded NULL parameters now raises a ValueError. Such certificates are invalid, but older versions of Java emitted them; previously they loaded with a deprecation warning.
Fixed cross-compilation of the CFFI bindings when PYO3_CROSS_LIB_DIR is set. The build now derives the Python include directory from PYO3_CROSS_LIB_DIR instead of querying the host interpreter, which previously caused the build to fail during cross-compilations for embedded systems, on hosts which have same-version Python development headers installed as the target Python.
Added support for signing and verifying X.509 certificates, certificate signing requests, and certificate revocation lists with /hazmat/primitives/asymmetric/mldsa keys, as well as loading certificates that contain ML-DSA public keys.
Added ~cryptography.hazmat.primitives.hpke.KEM.enc_length to ~cryptography.hazmat.primitives.hpke.KEM so callers can split the encapsulated key from the ciphertext returned by ~cryptography.hazmat.primitives.hpke.Suite.encrypt.
~cryptography.x509.verification.ExtensionPolicy.require_present, ~cryptography.x509.verification.ExtensionPolicy.may_be_present, and ~cryptography.x509.verification.ExtensionPolicy.require_not_present now accept any extension type. Previously only a fixed set of extension types was supported, which made it impossible to account for otherwise unrecognized critical extensions during path validation.
Added support for using ~cryptography.x509.Certificate, ~cryptography.x509.CertificateSigningRequest, and ~cryptography.x509.CertificateRevocationList as field types in /hazmat/asn1/index structures.
Added ~cryptography.hazmat.asn1.value_set, a class decorator that registers an enum.Enum subclass as an ASN.1 value set: members are encoded as their underlying value, and decoding fails if the decoded value does not match one of the declared members.
Added ~cryptography.x509.Name.from_bytes for parsing a ~cryptography.x509.Name from DER bytes, the inverse of ~cryptography.x509.Name.public_bytes.
Added the rsa_padding keyword-only parameter to ~cryptography.x509.CertificateBuilder.public_key. Passing the ~cryptography.hazmat.primitives.asymmetric.padding.PSS class (not an instance) encodes an RSA subject public key in the certificate's subjectPublicKeyInfo with the id-RSASSA-PSS OID and no parameters.
Added external mu (message representative) support to /hazmat/primitives/asymmetric/mldsa via the sign_mu and verify_mu methods, which sign and verify a precomputed 64-byte mu as defined in FIPS 204.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.1.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.1.
BACKWARDS INCOMPATIBLE: Support for Python 3.8 has been removed. cryptography now requires Python 3.9 or later.
BACKWARDS INCOMPATIBLE: Support for Python 3.8 has been removed. cryptography now requires Python 3.9 or later.
BACKWARDS INCOMPATIBLE: Loading an X.509 CRL whose inner TBSCertList.signature algorithm does not match the outer signatureAlgorithm now raises ValueError. Previously, such CRLs were parsed successfully and only rejected during signature validation.
Added support for /hazmat/primitives/asymmetric/mlkem and /hazmat/primitives/asymmetric/mldsa when using OpenSSL 3.5.0 or later, in addition to the existing AWS-LC and BoringSSL support. This means post-quantum algorithms are now available to users of our wheels.
Note: Going forward, we do not guarantee that all functionality in cryptography will be available when building against OpenSSL. See /statements/state-of-openssl for more information.
BACKWARDS INCOMPATIBLE: Support for Python 3.8 has been removed. cryptography now requires Python 3.9 or later.
BACKWARDS INCOMPATIBLE: Loading an X.509 CRL whose inner TBSCertList.signature algorithm does not match the outer signatureAlgorithm now raises ValueError . Previously, such CRLs were parsed successfully and only rejected during signature validation.
Added support for ML-KEM key encapsulation and ML-DSA signing when using OpenSSL 3.5.0 or later, in addition to the existing AWS-LC and BoringSSL support. This means post-quantum algorithms are now available to users of our wheels.
Note: Going forward, we do not guarantee that all functionality in cryptography will be available when building against OpenSSL. See The State of OpenSSL for pyca/cryptography for more information.
BACKWARDS INCOMPATIBLE: Support for binary elliptic curves (SECT* classes) has been removed. These curves are rarely used and have additional security…
Support for Python 3.8 is deprecated and will be removed in the next cryptography release.
BACKWARDS INCOMPATIBLE: Support for binary elliptic curves (SECT* classes) has been removed. These curves are rarely used and have additional security considerations that make them undesirable.
BACKWARDS INCOMPATIBLE: Support for OpenSSL 1.1.x has been removed. OpenSSL 3.0.0 or later is now required. LibreSSL, BoringSSL, and AWS-LC continue to be supported.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 4.1.
BACKWARDS INCOMPATIBLE: Loading keys with unsupported algorithms or keys with unsupported explicit curve encodings now raises ~cryptography.exceptions.UnsupportedAlgorithm instead of ValueError. This change affects ~cryptography.hazmat.primitives.serialization.load_pem_private_key, ~cryptography.hazmat.primitives.serialization.load_der_private_key, ~cryptography.hazmat.primitives.serialization.load_pem_public_key, ~cryptography.hazmat.primitives.serialization.load_der_public_key, and ~cryptography.x509.Certificate.public_key when called on certificates with unsupported public key algorithms.
BACKWARDS INCOMPATIBLE: When parsing elliptic curve private keys, we now reject keys that incorrectly encode a private key of the wrong length because such keys are impossible to process in a constant-time manner. We do not believe keys with this problem are in wide use, however we may revert this change based on the feedback we receive.
Deprecated passing 64-bit (8-byte) and 128-bit (16-byte) keys to ~cryptography.hazmat.decrepit.ciphers.algorithms.TripleDES. In a future release, only 192-bit (24-byte) keys will be accepted. Users should expand shorter keys themselves (e.g., for single DES: key + key + key, for two-key: key + key[:8]).
Updated the minimum supported Rust version (MSRV) to 1.83.0, from 1.74.0.
Support for x86_64 macOS (including publishing wheels) is deprecated and will be removed in the next release. We will switch to publishing an arm64 only wheel for macOS.
Support for 32-bit Windows (including publishing wheels) is deprecated and will be removed in the next release. Users should move to a 64-bit Python installation.
public_bytes and private_bytes methods on keys now raise TypeError (instead of ValueError) if an invalid encoding is provided for the given format.
Moved ~cryptography.hazmat.decrepit.ciphers.modes.CFB, ~cryptography.hazmat.decrepit.ciphers.modes.OFB, and ~cryptography.hazmat.decrepit.ciphers.modes.CFB8 into /hazmat/decrepit/index and deprecated them in the modes module. They will be removed from the modes module in 49.0.0.
Moved ~cryptography.hazmat.primitives.ciphers.algorithms.Camellia into /hazmat/decrepit/index and deprecated it in the cipher module. It will be removed from the cipher module in 49.0.0.
Added ~cryptography.hazmat.primitives.kdf.hkdf.HKDF.extract to ~cryptography.hazmat.primitives.kdf.hkdf.HKDF. The previous private implementation will be removed in 49.0.0.
Added support for loading elliptic curve keys that contain explicit encodings of the curves secp256r1, secp384r1, and secp521r1.
Added support for ~cryptography.hazmat.primitives.kdf.argon2.Argon2d and ~cryptography.hazmat.primitives.kdf.argon2.Argon2i when using OpenSSL 3.2.0+.
Added derive_into methods to ~cryptography.hazmat.primitives.kdf.hkdf.HKDF, ~cryptography.hazmat.primitives.kdf.hkdf.HKDFExpand, ~cryptography.hazmat.primitives.kdf.concatkdf.ConcatKDFHash, ~cryptography.hazmat.primitives.kdf.concatkdf.ConcatKDFHMAC, ~cryptography.hazmat.primitives.kdf.argon2.Argon2id, ~cryptography.hazmat.primitives.kdf.pbkdf2.PBKDF2HMAC, ~cryptography.hazmat.primitives.kdf.kbkdf.KBKDFHMAC, ~cryptography.hazmat.primitives.kdf.kbkdf.KBKDFCMAC, ~cryptography.hazmat.primitives.kdf.scrypt.Scrypt, and ~cryptography.hazmat.primitives.kdf.x963kdf.X963KDF to allow deriving keys directly into pre-allocated buffers.
Added encrypt_into and decrypt_into methods to ~cryptography.hazmat.primitives.ciphers.aead.AESCCM, ~cryptography.hazmat.primitives.ciphers.aead.AESGCM, ~cryptography.hazmat.primitives.ciphers.aead.AESGCMSIV, ~cryptography.hazmat.primitives.ciphers.aead.AESOCB3, ~cryptography.hazmat.primitives.ciphers.aead.AESSIV, and ~cryptography.hazmat.primitives.ciphers.aead.ChaCha20Poly1305 to allow encrypting directly into a pre-allocated buffer.
Added support for PKCS1v15 signing without DigestInfo using ~cryptography.hazmat.primitives.asymmetric.utils.NoDigestInfo.
Added ~cryptography.hazmat.primitives.hashes.Hash.hash, a one-shot method for computing hashes.
Added /hazmat/primitives/hpke support implementing 9180 for hybrid authenticated encryption.
Added new /hazmat/primitives/asymmetric/mlkem module with support for ML-KEM key encapsulation with AWS-LC and BoringSSL.
Note: Post-quantum algorithm support requires AWS-LC or BoringSSL. As we ship our wheels with OpenSSL, most users will not have access to these APIs yet. See /statements/state-of-openssl for more information on OpenSSL support.
Added new /hazmat/primitives/asymmetric/mldsa module with support for ML-DSA signing and verification with AWS-LC and BoringSSL.
Note: Post-quantum algorithm support requires AWS-LC or BoringSSL. As we ship our wheels with OpenSSL, most users will not have access to these APIs yet. See /statements/state-of-openssl for more information on OpenSSL support.
Added new /hazmat/asn1/index module with support for declaratively defining custom ASN.1 types and encoding/decoding them.
Fixed compilation when using LibreSSL 4.3.0 and OpenSSL 4.0.0.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.0.
Support for Python 3.8 is deprecated and will be removed in the next cryptography release.
BACKWARDS INCOMPATIBLE: Support for binary elliptic curves ( SECT* classes) has been removed. These curves are rarely used and have additional security considerations that make them undesirable.
BACKWARDS INCOMPATIBLE: Support for OpenSSL 1.1.x has been removed. OpenSSL 3.0.0 or later is now required. LibreSSL, BoringSSL, and AWS-LC continue to be supported.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 4.1.
BACKWARDS INCOMPATIBLE: Loading keys with unsupported algorithms or keys with unsupported explicit curve encodings now raises UnsupportedAlgorithm instead of ValueError . This change affects load_pem_private_key() , load_der_private_key() , load_pem_public_key() , load_der_public_key() , and public_key() when called on certificates with unsupported public key algorithms.
BACKWARDS INCOMPATIBLE: When parsing elliptic curve private keys, we now reject keys that incorrectly encode a private key of the wrong length because such keys are impossible to process in a constant-time manner. We do not believe keys with this problem are in wide use, however we may revert this change based on the feedback we receive.
Deprecated passing 64-bit (8-byte) and 128-bit (16-byte) keys to TripleDES . In a future release, only 192-bit (24-byte) keys will be accepted. Users should expand shorter keys themselves (e.g., for single DES: key + key + key , for two-key: key + key[:8] ).
Updated the minimum supported Rust version (MSRV) to 1.83.0, from 1.74.0.
Support for x86_64 macOS (including publishing wheels) is deprecated and will be removed in the next release. We will switch to publishing an arm64 only wheel for macOS.
Support for 32-bit Windows (including publishing wheels) is deprecated and will be removed in the next release. Users should move to a 64-bit Python installation.
public_bytes and private_bytes methods on keys now raise TypeError (instead of ValueError ) if an invalid encoding is provided for the given format .
Moved CFB , OFB , and CFB8 into Decrepit cryptography and deprecated them in the modes module. They will be removed from the modes module in 49.0.0.
Moved Camellia into Decrepit cryptography and deprecated it in the cipher module. It will be removed from the cipher module in 49.0.0.
Added extract() to HKDF . The previous private implementation will be removed in 49.0.0.
Added support for loading elliptic curve keys that contain explicit encodings of the curves secp256r1 , secp384r1 , and secp521r1 .
Added support for Argon2d and Argon2i when using OpenSSL 3.2.0+.
Added derive_into methods to HKDF , HKDFExpand , ConcatKDFHash , ConcatKDFHMAC , Argon2id , PBKDF2HMAC , KBKDFHMAC , KBKDFCMAC , Scrypt , and X963KDF to allow deriving keys directly into pre-allocated buffers.
Added encrypt_into and decrypt_into methods to AESCCM , AESGCM , AESGCMSIV , AESOCB3 , AESSIV , and ChaCha20Poly1305 to allow encrypting directly into a pre-allocated buffer.
Added support for PKCS1v15 signing without DigestInfo using NoDigestInfo .
Added hash() , a one-shot method for computing hashes.
Added HPKE (Hybrid Public Key Encryption) support implementing RFC 9180 for hybrid authenticated encryption.
Added new ML-KEM key encapsulation module with support for ML-KEM key encapsulation with AWS-LC and BoringSSL.
Note: Post-quantum algorithm support requires AWS-LC or BoringSSL. As we ship our wheels with OpenSSL, most users will not have access to these APIs yet. See The State of OpenSSL for pyca/cryptography for more information on OpenSSL support.
Added new ML-DSA signing module with support for ML-DSA signing and verification with AWS-LC and BoringSSL.
Note: Post-quantum algorithm support requires AWS-LC or BoringSSL. As we ship our wheels with OpenSSL, most users will not have access to these APIs yet. See The State of OpenSSL for pyca/cryptography for more information on OpenSSL support.
Added new ASN.1 module with support for declaratively defining custom ASN.1 types and encoding/decoding them.
Fixed compilation when using LibreSSL 4.3.0 and OpenSSL 4.0.0.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.0.
…buffers, which could lead to buffer overflow. CVE-2026-39892
SECURITY ISSUE: Fixed an issue where non-contiguous buffers could be passed to APIs that accept Python buffers, which could lead to buffer overflow. CVE-2026-39892
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.6.
Credit to Oleh Konko (1seal) for reporting the issue. CVE-2026-34073
SECURITY ISSUE: Fixed a bug where name constraints were not applied to peer names during verification when the leaf certificate contains a wildcard DNS SAN. Ordinary X.509 topologies are not affected by this bug, including those used by the Web PKI. Credit to Oleh Konko (1seal) for reporting the issue. CVE-2026-34073
Credit to XlabAI Team of Tencent Xuanwu Lab and Atuin Automated Vulnerability Discovery Engine for reporting the issue. CVE-2026-26007
An attacker could create a malicious public key that reveals portions of your private key when using certain uncommon elliptic curves (binary curves). This version now includes additional security checks to prevent this attack. This issue only affects binary elliptic curves, which are rarely used in real-world applications. Credit to XlabAI Team of Tencent Xuanwu Lab and Atuin Automated Vulnerability Discovery Engine for reporting the issue. CVE-2026-26007
Support for SECT* binary elliptic curves is deprecated and will be removed in the next release.
Dropped support for win_arm64 wheels_.
`Dropped support for win_arm64 wheels`_.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.5.
Fixed compilation when using LibreSSL 4.2.0.
Fixed compilation when using LibreSSL 4.2.0.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.4.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.4.
Fixed an issue where users installing via pip on Python 3.14 development versions would not properly install a dependency.
Fixed an issue where users installing via pip on Python 3.14 development versions would not properly install a dependency.
Fixed an issue building the free-threaded macOS 3.14 wheels.
BACKWARDS INCOMPATIBLE: Support for Python 3.7 has been removed.
BACKWARDS INCOMPATIBLE: Support for Python 3.7 has been removed.
Support for OpenSSL < 3.0 is deprecated and will be removed in the next release.
Support for x86_64 macOS (including publishing wheels) is deprecated and will be removed in two releases. We will switch to publishing an arm64 only wheel for macOS.
Support for 32-bit Windows (including publishing wheels) is deprecated and will be removed in two releases. Users should move to a 64-bit Python installation.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.3.
We now build ppc64le manylinux wheels and publish them to PyPI.
We now build win_arm64 (Windows on Arm) wheels and publish them to PyPI.
Added support for free-threaded Python 3.14.
Removed the deprecated get_attribute_for_oid method on ~cryptography.x509.CertificateSigningRequest. Users should use ~cryptography.x509.Attributes.get_attribute_for_oid instead.
Removed the deprecated CAST5, SEED, IDEA, and Blowfish classes from the cipher module. These are still available in /hazmat/decrepit/index.
In X.509, when performing a PSS signature with a SHA-3 hash, it is now encoded with the official NIST SHA3 OID.
Added a function to support an upcoming pyOpenSSL release.
Added a function to support an upcoming pyOpenSSL release.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.2.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.2.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.1.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.1.
Fixed decrypting PKCS#8 files encrypted with SHA1-RC4. (This is not considered secure, and is supported only for backwards compatibility.)
Fixed decrypting PKCS#8 files encrypted with SHA1-RC4. (This is not considered secure, and is supported only for backwards compatibility.)
Fixed decrypting PKCS#8 files encrypted with long salts (this impacts keys encrypted by Bouncy Castle).
Fixed decrypting PKCS#8 files encrypted with long salts (this impacts keys encrypted by Bouncy Castle).
Fixed decrypting PKCS#8 files encrypted with DES-CBC-MD5. While wildly insecure, this remains prevalent.
Fixed using mypy with cryptography on older versions of Python.
Fixed using mypy with cryptography on older versions of Python.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.0.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.0.
BACKWARDS INCOMPATIBLE: Made SSH private key loading more consistent with other private key loading: ~cryptography.hazmat.primitives.serialization.loa…
Support for Python 3.7 is deprecated and will be removed in the next cryptography release.
Updated the minimum supported Rust version (MSRV) to 1.74.0, from 1.65.0.
Added support for serialization of PKCS#12 Java truststores in ~cryptography.hazmat.primitives.serialization.pkcs12.serialize_java_truststore
Added ~cryptography.hazmat.primitives.kdf.argon2.Argon2id.derive_phc_encoded and ~cryptography.hazmat.primitives.kdf.argon2.Argon2id.verify_phc_encoded methods to support password hashing in the PHC string format
Added support for PKCS7 decryption and encryption using AES-256 as the content algorithm, in addition to AES-128.
BACKWARDS INCOMPATIBLE: Made SSH private key loading more consistent with other private key loading: ~cryptography.hazmat.primitives.serialization.load_ssh_private_key now raises a TypeError if the key is unencrypted but a password is provided (previously no exception was raised), and raises a TypeError if the key is encrypted but no password is provided (previously a ValueError was raised).
Added __copy__ to the ~cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePrivateKey, ~cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePublicKey, ~cryptography.hazmat.primitives.asymmetric.ed25519.Ed25519PublicKey, ~cryptography.hazmat.primitives.asymmetric.ed25519.Ed25519PrivateKey, ~cryptography.hazmat.primitives.asymmetric.ed448.Ed448PublicKey, ~cryptography.hazmat.primitives.asymmetric.ed448.Ed448PrivateKey, ~cryptography.hazmat.primitives.asymmetric.x25519.X25519PublicKey, ~cryptography.hazmat.primitives.asymmetric.x25519.X25519PrivateKey, ~cryptography.hazmat.primitives.asymmetric.x448.X448PublicKey, ~cryptography.hazmat.primitives.asymmetric.x448.X448PrivateKey, ~cryptography.hazmat.primitives.asymmetric.rsa.RSAPrivateKey, ~cryptography.hazmat.primitives.asymmetric.rsa.RSAPublicKey, ~cryptography.hazmat.primitives.asymmetric.dsa.DSAPrivateKey, ~cryptography.hazmat.primitives.asymmetric.dsa.DSAPublicKey, ~cryptography.hazmat.primitives.asymmetric.dh.DHPrivateKey, and ~cryptography.hazmat.primitives.asymmetric.dh.DHPublicKey abstract base classes.
We significantly refactored how private key loading ( ~cryptography.hazmat.primitives.serialization.load_pem_private_key and ~cryptography.hazmat.primitives.serialization.load_der_private_key) works. This is intended to be backwards compatible for all well-formed keys, therefore if you discover a key that now raises an exception, please file a bug with instructions for reproducing.
Added unsafe_skip_rsa_key_validation keyword-argument to ~cryptography.hazmat.primitives.serialization.load_ssh_private_key.
Added ~cryptography.hazmat.primitives.hashes.XOFHash to support repeated ~cryptography.hazmat.primitives.hashes.XOFHash.squeeze operations on extendable output functions.
Added ~cryptography.x509.ocsp.OCSPResponseBuilder.add_response_by_hash method to allow creating OCSP responses using certificate hash values rather than full certificates.
Extended the X.509 path validation API to support user-configured extension policies via the PolicyBuilder.extension_policies method.
Deprecated the subject, verification_time and max_chain_depth properties on ~cryptography.x509.verification.ClientVerifier and ~cryptography.x509.verification.ServerVerifier in favor of a new policy property. These properties will be removed in the next release of cryptography.
BACKWARDS INCOMPATIBLE: The VerifiedClient.subject property can now be None since a custom extension policy may allow certificates without a Subject Alternative Name extension.
Changed the behavior when the OpenSSL 3 legacy provider fails to load. Instead of raising an exception, a warning is now emitted. The CRYPTOGRAPHY_OPENSSL_NO_LEGACY environment variable can still be used to disable the legacy provider at runtime.
Added support for the CRYPTOGRAPHY_BUILD_OPENSSL_NO_LEGACY environment variable during build time, which prevents the library from ever attempting to load the legacy provider.
Added support for the ~cryptography.x509.PrivateKeyUsagePeriod X.509 extension. This extension defines the period during which the private key corresponding to the certificate's public key may be used.
Added support for compiling against `aws-lc`_.
Parsing X.509 structures now more strictly enforces that Name structures do not have malformed ASN.1.
We now publish py311 wheels that utilize the faster pyo3::buffer::PyBuffer interface, resulting in significantly improved performance for operations involving small buffers.
Added ~cryptography.hazmat.primitives.serialization.ssh_key_fingerprint for computing fingerprints of SSH public keys.
Added support for deterministic ECDSA signing via the new keyword-only argument ecdsa_deterministic in ~cryptography.x509.CertificateBuilder.sign, ~cryptography.x509.CertificateRevocationListBuilder.sign and ~cryptography.x509.CertificateSigningRequestBuilder.sign.
Support for Python 3.7 is deprecated and will be removed in the next cryptography release.
Updated the minimum supported Rust version (MSRV) to 1.74.0, from 1.65.0.
Added support for serialization of PKCS#12 Java truststores in serialize_java_truststore()
Added derive_phc_encoded() and verify_phc_encoded() methods to support password hashing in the PHC string format
Added support for PKCS7 decryption and encryption using AES-256 as the content algorithm, in addition to AES-128.
BACKWARDS INCOMPATIBLE: Made SSH private key loading more consistent with other private key loading: load_ssh_private_key() now raises a TypeError if the key is unencrypted but a password is provided (previously no exception was raised), and raises a TypeError if the key is encrypted but no password is provided (previously a ValueError was raised).
Added copy to the EllipticCurvePrivateKey , EllipticCurvePublicKey , Ed25519PublicKey , Ed25519PrivateKey , Ed448PublicKey , Ed448PrivateKey , X25519PublicKey , X25519PrivateKey , X448PublicKey , X448PrivateKey , RSAPrivateKey , RSAPublicKey , DSAPrivateKey , DSAPublicKey , DHPrivateKey , and DHPublicKey abstract base classes.
We significantly refactored how private key loading ( load_pem_private_key() and load_der_private_key() ) works. This is intended to be backwards compatible for all well-formed keys, therefore if you discover a key that now raises an exception, please file a bug with instructions for reproducing.
Added unsafe_skip_rsa_key_validation keyword-argument to load_ssh_private_key() .
Added XOFHash to support repeated squeeze() operations on extendable output functions.
Added add_response_by_hash() method to allow creating OCSP responses using certificate hash values rather than full certificates.
Extended the X.509 path validation API to support user-configured extension policies via the PolicyBuilder.extension_policies method.
Deprecated the subject , verification_time and max_chain_depth properties on ClientVerifier and ServerVerifier in favor of a new policy property. These properties will be removed in the next release of cryptography .
BACKWARDS INCOMPATIBLE: The VerifiedClient.subject property can now be None since a custom extension policy may allow certificates without a Subject Alternative Name extension.
Changed the behavior when the OpenSSL 3 legacy provider fails to load. Instead of raising an exception, a warning is now emitted. The CRYPTOGRAPHY_OPENSSL_NO_LEGACY environment variable can still be used to disable the legacy provider at runtime.
Added support for the CRYPTOGRAPHY_BUILD_OPENSSL_NO_LEGACY environment variable during build time, which prevents the library from ever attempting to load the legacy provider.
Added support for the PrivateKeyUsagePeriod X.509 extension. This extension defines the period during which the private key corresponding to the certificate’s public key may be used.
Added support for compiling against aws-lc .
Parsing X.509 structures now more strictly enforces that Name structures do not have malformed ASN.1.
We now publish py311 wheels that utilize the faster pyo3::buffer::PyBuffer interface, resulting in significantly improved performance for operations involving small buffers.
Added ssh_key_fingerprint() for computing fingerprints of SSH public keys.
Added support for deterministic ECDSA signing via the new keyword-only argument ecdsa_deterministic in sign() , sign() and sign() .
Fixed compilation when using LibreSSL 4.1.0.
Fixed compilation when using LibreSSL 4.1.0.
We now build wheels for PyPy 3.11.
We now build wheels for PyPy 3.11.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.4.1.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.4.1.
We now build armv7l manylinux wheels and publish them to PyPI.
We now build manylinux_2_34 wheels and publish them to PyPI.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.9.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.9.
Deprecated Python 3.7 support. Python 3.7 is no longer supported by the Python core team. Support for Python 3.7 will be removed in a future cryptography release.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.4.0.
macOS wheels are now built against the macOS 10.13 SDK. Users on older versions of macOS should upgrade, or they will need to build cryptography themselves.
Enforce the 5280 requirement that extended key usage extensions must not be empty.
Added support for timestamp extraction to the ~cryptography.fernet.MultiFernet class.
Relax the Authority Key Identifier requirements on root CA certificates during X.509 verification to allow fields permitted by 5280 but forbidden by the CA/Browser BRs.
Added support for ~cryptography.hazmat.primitives.kdf.argon2.Argon2id when using OpenSSL 3.2.0+.
Added support for the ~cryptography.x509.Admissions certificate extension.
Added basic support for PKCS7 decryption (including S/MIME 3.2) via ~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der, ~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_pem, and ~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_smime.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.9.
Deprecated Python 3.7 support. Python 3.7 is no longer supported by the Python core team. Support for Python 3.7 will be removed in a future cryptography release.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.4.0.
macOS wheels are now built against the macOS 10.13 SDK. Users on older versions of macOS should upgrade, or they will need to build cryptography themselves.
Enforce the RFC 5280 requirement that extended key usage extensions must not be empty.
Added support for timestamp extraction to the MultiFernet class.
Relax the Authority Key Identifier requirements on root CA certificates during X.509 verification to allow fields permitted by RFC 5280 but forbidden by the CA/Browser BRs.
Added support for Argon2id when using OpenSSL 3.2.0+.
Added support for the Admissions certificate extension.
Added basic support for PKCS7 decryption (including S/MIME 3.2) via pkcs7_decrypt_der() , pkcs7_decrypt_pem() , and pkcs7_decrypt_smime() .
Fixed release metadata for cryptography-vectors
Fixed release metadata for cryptography-vectors
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.3.2.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.3.2.
BACKWARDS INCOMPATIBLE: Support for OpenSSL less than 1.1.1e has been removed. Users on older version of OpenSSL will need to upgrade.
BACKWARDS INCOMPATIBLE: Support for OpenSSL less than 1.1.1e has been removed. Users on older version of OpenSSL will need to upgrade.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.8.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.3.1.
Updated the minimum supported Rust version (MSRV) to 1.65.0, from 1.63.0.
~cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key now enforces a minimum RSA key size of 1024-bit. Note that 1024-bit is still considered insecure, users should generally use a key size of 2048-bits.
~cryptography.hazmat.primitives.serialization.pkcs7.serialize_certificates now emits ASN.1 that more closely follows the recommendations in 2315.
Added new /hazmat/decrepit/index module which contains outdated and insecure cryptographic primitives. CAST5, SEED, IDEA, and Blowfish, which were deprecated in 37.0.0, have been added to this module. They will be removed from the cipher module in 45.0.0.
Moved ~cryptography.hazmat.primitives.ciphers.algorithms.TripleDES and ~cryptography.hazmat.primitives.ciphers.algorithms.ARC4 into /hazmat/decrepit/index and deprecated them in the cipher module. They will be removed from the cipher module in 48.0.0.
Added support for deterministic ~cryptography.hazmat.primitives.asymmetric.ec.ECDSA (6979)
Added support for client certificate verification to the X.509 path validation APIs in the form of ~cryptography.x509.verification.ClientVerifier, ~cryptography.x509.verification.VerifiedClient, and PolicyBuilder ~cryptography.x509.verification.PolicyBuilder.build_client_verifier.
Added Certificate ~cryptography.x509.Certificate.public_key_algorithm_oid and Certificate Signing Request ~cryptography.x509.CertificateSigningRequest.public_key_algorithm_oid to determine the ~cryptography.hazmat._oid.PublicKeyAlgorithmOID Object Identifier of the public key found inside the certificate.
Added ~cryptography.x509.InvalidityDate.invalidity_date_utc, a timezone-aware alternative to the naïve datetime attribute ~cryptography.x509.InvalidityDate.invalidity_date.
Added support for parsing empty DN string in ~cryptography.x509.Name.from_rfc4514_string.
Added the following properties that return timezone-aware datetime objects: ~cryptography.x509.ocsp.OCSPResponse.produced_at_utc, ~cryptography.x509.ocsp.OCSPResponse.revocation_time_utc, ~cryptography.x509.ocsp.OCSPResponse.this_update_utc, ~cryptography.x509.ocsp.OCSPResponse.next_update_utc, ~cryptography.x509.ocsp.OCSPSingleResponse.revocation_time_utc, ~cryptography.x509.ocsp.OCSPSingleResponse.this_update_utc, ~cryptography.x509.ocsp.OCSPSingleResponse.next_update_utc, These are timezone-aware variants of existing properties that return naïve datetime objects.
Added ~cryptography.hazmat.primitives.asymmetric.rsa.rsa_recover_private_exponent
Added ~cryptography.hazmat.primitives.ciphers.CipherContext.reset_nonce for altering the nonce of a cipher context without initializing a new instance. See the docs for additional restrictions.
~cryptography.x509.NameAttribute now raises an exception when attempting to create a common name whose length is shorter or longer than 5280 permits.
Added basic support for PKCS7 encryption (including SMIME) via ~cryptography.hazmat.primitives.serialization.pkcs7.PKCS7EnvelopeBuilder.
BACKWARDS INCOMPATIBLE: Support for OpenSSL less than 1.1.1e has been removed. Users on older version of OpenSSL will need to upgrade.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.8.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.3.1.
Updated the minimum supported Rust version (MSRV) to 1.65.0, from 1.63.0.
generate_private_key() now enforces a minimum RSA key size of 1024-bit. Note that 1024-bit is still considered insecure, users should generally use a key size of 2048-bits.
serialize_certificates() now emits ASN.1 that more closely follows the recommendations in RFC 2315 .
Added new Decrepit cryptography module which contains outdated and insecure cryptographic primitives. CAST5 , SEED , IDEA , and Blowfish , which were deprecated in 37.0.0, have been added to this module. They will be removed from the cipher module in 45.0.0.
Moved TripleDES and ARC4 into Decrepit cryptography and deprecated them in the cipher module. They will be removed from the cipher module in 48.0.0.
Added support for deterministic ECDSA ( RFC 6979 )
Added support for client certificate verification to the X.509 path validation APIs in the form of ClientVerifier , VerifiedClient , and PolicyBuilder build_client_verifier() .
Added Certificate public_key_algorithm_oid and Certificate Signing Request public_key_algorithm_oid to determine the PublicKeyAlgorithmOID Object Identifier of the public key found inside the certificate.
Added invalidity_date_utc , a timezone-aware alternative to the naïve datetime attribute invalidity_date .
Added support for parsing empty DN string in from_rfc4514_string() .
Added the following properties that return timezone-aware datetime objects: produced_at_utc() , revocation_time_utc() , this_update_utc() , next_update_utc() , revocation_time_utc() , this_update_utc() , next_update_utc() , These are timezone-aware variants of existing properties that return naïve datetime objects.
Added rsa_recover_private_exponent()
Added reset_nonce() for altering the nonce of a cipher context without initializing a new instance. See the docs for additional restrictions.
NameAttribute now raises an exception when attempting to create a common name whose length is shorter or longer than RFC 5280 permits.
Added basic support for PKCS7 encryption (including SMIME) via PKCS7EnvelopeBuilder .
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.2.2.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.2.2.
Restored Windows 7 compatibility for our pre-built wheels. Note that we do not test on Windows 7 and wheels for our next release will not support it.
Restored Windows 7 compatibility for our pre-built wheels. Note that we do not test on Windows 7 and wheels for our next release will not support it. Microsoft no longer provides support for Windows 7 and users are encouraged to upgrade.
Fixed compilation when using LibreSSL 3.9.1.
Fixed compilation when using LibreSSL 3.9.1.
Limit the number of name constraint checks that will be performed in X.509 path validation to protect against denial of service attacks.
Limit the number of name constraint checks that will be performed in X.509 path validation to protect against denial of service attacks.
Upgrade pyo3 version, which fixes building on PowerPC.
Credit to Alexander-Programming for reporting the issue. CVE-2024-26130
Fixed a null-pointer-dereference and segfault that could occur when creating a PKCS#12 bundle. Credit to Alexander-Programming for reporting the issue. CVE-2024-26130
Fixed ASN.1 encoding for PKCS7/SMIME signed messages. The fields SMIMECapabilities and SignatureAlgorithmIdentifier should now be correctly encoded according to the definitions in 2633 3370.
Fixed an initialization issue that caused key loading failures for some users.
Fixed an initialization issue that caused key loading failures for some users.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.2.1.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.2.1.
Fixed an issue that prevented the use of Python buffer protocol objects in sign and verify methods on asymmetric keys.
Fixed an issue with incorrect keyword-argument naming with EllipticCurvePrivateKey ~cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePrivateKey.exchange, X25519PrivateKey ~cryptography.hazmat.primitives.asymmetric.x25519.X25519PrivateKey.exchange, X448PrivateKey ~cryptography.hazmat.primitives.asymmetric.x448.X448PrivateKey.exchange, and DHPrivateKey ~cryptography.hazmat.primitives.asymmetric.dh.DHPrivateKey.exchange.
Fixed an issue with incorrect keyword-argument naming with EllipticCurvePrivateKey ~cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePrivateK
Fixed an issue with incorrect keyword-argument naming with EllipticCurvePrivateKey ~cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePrivateKey.sign.
Resolved compatibility issue with loading certain RSA public keys in ~cryptography.hazmat.primitives.serialization.load_pem_public_key.
Fixed an issue with incorrect keyword-argument naming with EllipticCurvePrivateKey sign() .
Resolved compatibility issue with loading certain RSA public keys in load_pem_public_key() .
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.7.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.7.
BACKWARDS INCOMPATIBLE: Loading a PKCS7 with no content field using ~cryptography.hazmat.primitives.serialization.pkcs7.load_pem_pkcs7_certificates or ~cryptography.hazmat.primitives.serialization.pkcs7.load_der_pkcs7_certificates will now raise a ValueError rather than return an empty list.
Parsing SSH certificates no longer permits malformed critical options with values, as documented in the 41.0.2 release notes.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.2.0.
Updated the minimum supported Rust version (MSRV) to 1.63.0, from 1.56.0.
We now publish both py37 and py39 abi3 wheels. This should resolve some errors relating to initializing a module multiple times per process.
Support ~cryptography.hazmat.primitives.asymmetric.padding.PSS for X.509 certificate signing requests and certificate revocation lists with the keyword-only argument rsa_padding on the sign methods for ~cryptography.x509.CertificateSigningRequestBuilder and ~cryptography.x509.CertificateRevocationListBuilder.
Added support for obtaining X.509 certificate signing request signature algorithm parameters (including PSS) via ~cryptography.x509.CertificateSigningRequest.signature_algorithm_parameters.
Added support for obtaining X.509 certificate revocation list signature algorithm parameters (including PSS) via ~cryptography.x509.CertificateRevocationList.signature_algorithm_parameters.
Added mgf property to ~cryptography.hazmat.primitives.asymmetric.padding.PSS.
Added algorithm and mgf properties to ~cryptography.hazmat.primitives.asymmetric.padding.OAEP.
Added the following properties that return timezone-aware datetime objects: ~cryptography.x509.Certificate.not_valid_before_utc, ~cryptography.x509.Certificate.not_valid_after_utc, ~cryptography.x509.RevokedCertificate.revocation_date_utc, ~cryptography.x509.CertificateRevocationList.next_update_utc, ~cryptography.x509.CertificateRevocationList.last_update_utc. These are timezone-aware variants of existing properties that return naïve datetime objects.
Deprecated the following properties that return naïve datetime objects: ~cryptography.x509.Certificate.not_valid_before, ~cryptography.x509.Certificate.not_valid_after, ~cryptography.x509.RevokedCertificate.revocation_date, ~cryptography.x509.CertificateRevocationList.next_update, ~cryptography.x509.CertificateRevocationList.last_update in favor of the new timezone-aware variants mentioned above.
Added support for ~cryptography.hazmat.primitives.ciphers.algorithms.ChaCha20 on LibreSSL.
Added support for RSA PSS signatures in PKCS7 with ~cryptography.hazmat.primitives.serialization.pkcs7.PKCS7SignatureBuilder.add_signer.
In the next release (43.0.0) of cryptography, loading an X.509 certificate with a negative serial number will raise an exception. This has been deprecated since 36.0.0.
Added support for ~cryptography.hazmat.primitives.ciphers.aead.AESGCMSIV when using OpenSSL 3.2.0+.
Added the X.509 path validation APIs for ~cryptography.x509.Certificate chains. These APIs should be considered unstable and not subject to our stability guarantees until documented as such in a future release.
Added support for ~cryptography.hazmat.primitives.ciphers.algorithms.SM4 ~cryptography.hazmat.primitives.ciphers.modes.GCM when using OpenSSL 3.0 or greater.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.7.
BACKWARDS INCOMPATIBLE: Loading a PKCS7 with no content field using load_pem_pkcs7_certificates() or load_der_pkcs7_certificates() will now raise a ValueError rather than return an empty list.
Parsing SSH certificates no longer permits malformed critical options with values, as documented in the 41.0.2 release notes.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.2.0.
Updated the minimum supported Rust version (MSRV) to 1.63.0, from 1.56.0.
We now publish both py37 and py39 abi3 wheels. This should resolve some errors relating to initializing a module multiple times per process.
Support PSS for X.509 certificate signing requests and certificate revocation lists with the keyword-only argument rsa_padding on the sign methods for CertificateSigningRequestBuilder and CertificateRevocationListBuilder .
Added support for obtaining X.509 certificate signing request signature algorithm parameters (including PSS) via signature_algorithm_parameters() .
Added support for obtaining X.509 certificate revocation list signature algorithm parameters (including PSS) via signature_algorithm_parameters() .
Added mgf property to PSS .
Added algorithm and mgf properties to OAEP .
Added the following properties that return timezone-aware datetime objects: not_valid_before_utc() , not_valid_after_utc() , revocation_date_utc() , next_update_utc() , last_update_utc() . These are timezone-aware variants of existing properties that return naïve datetime objects.
Deprecated the following properties that return naïve datetime objects: not_valid_before() , not_valid_after() , revocation_date() , next_update() , last_update() in favor of the new timezone-aware variants mentioned above.
Added support for ChaCha20 on LibreSSL.
Added support for RSA PSS signatures in PKCS7 with add_signer() .
In the next release (43.0.0) of cryptography, loading an X.509 certificate with a negative serial number will raise an exception. This has been deprecated since 36.0.0.
Added support for AESGCMSIV when using OpenSSL 3.2.0+.
Added the X.509 path validation APIs for Certificate chains. These APIs should be considered unstable and not subject to our stability guarantees until documented as such in a future release.
Added support for SM4 GCM when using OpenSSL 3.0 or greater.
Fixed compilation when using LibreSSL 3.8.2.
Fixed compilation when using LibreSSL 3.8.2.
Credit to pkuzco for reporting the issue. CVE-2023-49083
Fixed a null-pointer-dereference and segfault that could occur when loading certificates from a PKCS#7 bundle. Credit to pkuzco for reporting the issue. CVE-2023-49083
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.1.4.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.1.4.
Added a function to support an upcoming pyOpenSSL release.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.1.3.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.1.3.
Fixed performance regression loading DH public keys.
Fixed performance regression loading DH public keys.
Fixed a memory leak when using ~cryptography.hazmat.primitives.ciphers.aead.ChaCha20Poly1305.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.1.2.
Fixed bugs in creating and parsing SSH certificates where critical options with values were handled incorrectly. Certificates are now created correctl
Fixed bugs in creating and parsing SSH certificates where critical options with values were handled incorrectly. Certificates are now created correctly and parsing accepts correct values as well as the previously generated invalid forms with a warning. In the next release, support for parsing these invalid forms will be removed.
Temporarily allow invalid ECDSA signature algorithm parameters in X.509 certificates, which are generated by older versions of Java.
Temporarily allow invalid ECDSA signature algorithm parameters in X.509 certificates, which are generated by older versions of Java.
Allow null bytes in pass phrases when serializing private keys.
BACKWARDS INCOMPATIBLE: Support for OpenSSL less than 1.1.1d has been removed. Users on older version of OpenSSL will need to upgrade.
BACKWARDS INCOMPATIBLE: Support for OpenSSL less than 1.1.1d has been removed. Users on older version of OpenSSL will need to upgrade.
BACKWARDS INCOMPATIBLE: Support for Python 3.6 has been removed.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.6.
Updated the minimum supported Rust version (MSRV) to 1.56.0, from 1.48.0.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.1.1.
Added support for the ~cryptography.x509.OCSPAcceptableResponses OCSP extension.
Added support for the ~cryptography.x509.MSCertificateTemplate proprietary Microsoft certificate extension.
Implemented support for equality checks on all asymmetric public key types.
Added support for aes256-gcm@openssh.com encrypted keys in ~cryptography.hazmat.primitives.serialization.load_ssh_private_key.
Added support for obtaining X.509 certificate signature algorithm parameters (including PSS) via ~cryptography.x509.Certificate.signature_algorithm_parameters.
Support signing ~cryptography.hazmat.primitives.asymmetric.padding.PSS X.509 certificates via the new keyword-only argument rsa_padding on ~cryptography.x509.CertificateBuilder.sign.
Added support for ~cryptography.hazmat.primitives.ciphers.aead.ChaCha20Poly1305 on BoringSSL.
BACKWARDS INCOMPATIBLE: Support for OpenSSL less than 1.1.1d has been removed. Users on older version of OpenSSL will need to upgrade.
BACKWARDS INCOMPATIBLE: Support for Python 3.6 has been removed.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.6.
Updated the minimum supported Rust version (MSRV) to 1.56.0, from 1.48.0.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.1.1.
Added support for the OCSPAcceptableResponses OCSP extension.
Added support for the MSCertificateTemplate proprietary Microsoft certificate extension.
Implemented support for equality checks on all asymmetric public key types.
Added support for aes256-gcm@openssh.com encrypted keys in load_ssh_private_key() .
Added support for obtaining X.509 certificate signature algorithm parameters (including PSS) via signature_algorithm_parameters() .
Support signing PSS X.509 certificates via the new keyword-only argument rsa_padding on sign() .
Added support for ChaCha20Poly1305 on BoringSSL.
Fixed compilation when using LibreSSL 3.7.2.
Fixed compilation when using LibreSSL 3.7.2.
Added some functions to support an upcoming pyOpenSSL release.
Fixed a bug where certain operations would fail if an object happened to be in the top-half of the memory-space. This only impacted 32-bit systems.
Fixed a bug where certain operations would fail if an object happened to be in the top-half of the memory-space. This only impacted 32-bit systems.
BACKWARDS INCOMPATIBLE: As announced in the 39.0.0 changelog, the way cryptography links OpenSSL has changed. This only impacts users who build crypto…
BACKWARDS INCOMPATIBLE: As announced in the 39.0.0 changelog, the way cryptography links OpenSSL has changed. This only impacts users who build cryptography from source (i.e., not from a wheel), and specify their own version of OpenSSL. For those users, the CFLAGS, LDFLAGS, INCLUDE, LIB, and CRYPTOGRAPHY_SUPPRESS_LINK_FLAGS environment variables are no longer valid. Instead, users need to configure their builds `as documented here`_.
Support for Python 3.6 is deprecated and will be removed in the next release.
Deprecated the current minimum supported Rust version (MSRV) of 1.48.0. In the next release we will raise MSRV to 1.56.0. Users with the latest pip will typically get a wheel and not need Rust installed, but check /installation for documentation on installing a newer rustc if required.
Deprecated support for OpenSSL less than 1.1.1d. The next release of cryptography will drop support for older versions.
Deprecated support for DSA keys in ~cryptography.hazmat.primitives.serialization.load_ssh_public_key and ~cryptography.hazmat.primitives.serialization.load_ssh_private_key.
Deprecated support for OpenSSH serialization in ~cryptography.hazmat.primitives.asymmetric.dsa.DSAPublicKey and ~cryptography.hazmat.primitives.asymmetric.dsa.DSAPrivateKey.
The minimum supported version of PyPy3 is now 7.3.10.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.1.0.
Added support for parsing SSH certificates in addition to public keys with ~cryptography.hazmat.primitives.serialization.load_ssh_public_identity. ~cryptography.hazmat.primitives.serialization.load_ssh_public_key continues to support only public keys.
Added support for generating SSH certificates with ~cryptography.hazmat.primitives.serialization.SSHCertificateBuilder.
Added ~cryptography.x509.Certificate.verify_directly_issued_by to ~cryptography.x509.Certificate.
Added a check to ~cryptography.x509.NameConstraints to ensure that ~cryptography.x509.DNSName constraints do not contain any * wildcards.
Removed many unused CFFI OpenSSL bindings. This will not impact you unless you are using cryptography to directly invoke OpenSSL's C API. Note that these have never been considered a stable, supported, public API by cryptography, this note is included as a courtesy.
The X.509 builder classes now raise UnsupportedAlgorithm instead of ValueError if an unsupported hash algorithm is passed.
Added public union type aliases for type hinting:
Asymmetric types: ~cryptography.hazmat.primitives.asymmetric.types.PublicKeyTypes, ~cryptography.hazmat.primitives.asymmetric.types.PrivateKeyTypes, ~cryptography.hazmat.primitives.asymmetric.types.CertificatePublicKeyTypes, ~cryptography.hazmat.primitives.asymmetric.types.CertificateIssuerPublicKeyTypes, ~cryptography.hazmat.primitives.asymmetric.types.CertificateIssuerPrivateKeyTypes.
SSH keys: ~cryptography.hazmat.primitives.serialization.SSHPublicKeyTypes, ~cryptography.hazmat.primitives.serialization.SSHPrivateKeyTypes, ~cryptography.hazmat.primitives.serialization.SSHCertPublicKeyTypes, ~cryptography.hazmat.primitives.serialization.SSHCertPrivateKeyTypes.
PKCS12: ~cryptography.hazmat.primitives.serialization.pkcs12.PKCS12PrivateKeyTypes
PKCS7: ~cryptography.hazmat.primitives.serialization.pkcs7.PKCS7HashTypes, ~cryptography.hazmat.primitives.serialization.pkcs7.PKCS7PrivateKeyTypes.
Two-factor: ~cryptography.hazmat.primitives.twofactor.hotp.HOTPHashTypes
Deprecated previously undocumented but not private type aliases in the cryptography.hazmat.primitives.asymmetric.types module in favor of new ones above.
BACKWARDS INCOMPATIBLE: As announced in the 39.0.0 changelog, the way cryptography links OpenSSL has changed. This only impacts users who build cryptography from source (i.e., not from a wheel ), and specify their own version of OpenSSL. For those users, the CFLAGS , LDFLAGS , INCLUDE , LIB , and CRYPTOGRAPHY_SUPPRESS_LINK_FLAGS environment variables are no longer valid. Instead, users need to configure their builds as documented here .
Support for Python 3.6 is deprecated and will be removed in the next release.
Deprecated the current minimum supported Rust version (MSRV) of 1.48.0. In the next release we will raise MSRV to 1.56.0. Users with the latest pip will typically get a wheel and not need Rust installed, but check Installation for documentation on installing a newer rustc if required.
Deprecated support for OpenSSL less than 1.1.1d. The next release of cryptography will drop support for older versions.
Deprecated support for DSA keys in load_ssh_public_key() and load_ssh_private_key() .
Deprecated support for OpenSSH serialization in DSAPublicKey and DSAPrivateKey .
The minimum supported version of PyPy3 is now 7.3.10.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.1.0.
Added support for parsing SSH certificates in addition to public keys with load_ssh_public_identity() . load_ssh_public_key() continues to support only public keys.
Added support for generating SSH certificates with SSHCertificateBuilder .
Added verify_directly_issued_by() to Certificate .
Added a check to NameConstraints to ensure that DNSName constraints do not contain any * wildcards.
Removed many unused CFFI OpenSSL bindings. This will not impact you unless you are using cryptography to directly invoke OpenSSL’s C API. Note that these have never been considered a stable, supported, public API by cryptography , this note is included as a courtesy.
The X.509 builder classes now raise UnsupportedAlgorithm instead of ValueError if an unsupported hash algorithm is passed.
Added public union type aliases for type hinting:
Asymmetric types: PublicKeyTypes , PrivateKeyTypes , CertificatePublicKeyTypes , CertificateIssuerPublicKeyTypes , CertificateIssuerPrivateKeyTypes .
SSH keys: SSHPublicKeyTypes , SSHPrivateKeyTypes , SSHCertPublicKeyTypes , SSHCertPrivateKeyTypes .
PKCS12: PKCS12PrivateKeyTypes
PKCS7: PKCS7HashTypes , PKCS7PrivateKeyTypes .
Two-factor: HOTPHashTypes
Deprecated previously undocumented but not private type aliases in the cryptography.hazmat.primitives.asymmetric.types module in favor of new ones above.
Fixed a bug where the content type header was not properly encoded for PKCS7 signatures when using the Text option and SMIME encoding.
Fixed a bug where the content type header was not properly encoded for PKCS7 signatures when using the Text option and SMIME encoding.
SECURITY ISSUE - Fixed a bug where Cipher.update_into accepted Python buffer protocol objects, but allowed immutable buffers. CVE-2023-23931
SECURITY ISSUE - Fixed a bug where Cipher.update_into accepted Python buffer protocol objects, but allowed immutable buffers. CVE-2023-23931
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.0.8.
BACKWARDS INCOMPATIBLE: Support for OpenSSL 1.1.0 has been removed. Users on older version of OpenSSL will need to upgrade.
BACKWARDS INCOMPATIBLE: Support for OpenSSL 1.1.0 has been removed. Users on older version of OpenSSL will need to upgrade.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.5. The new minimum LibreSSL version is 3.5.0. Going forward our policy is to support versions of LibreSSL that are available in versions of OpenBSD that are still receiving security support.
BACKWARDS INCOMPATIBLE: Removed the encode_point and from_encoded_point methods on ~cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePublicNumbers, which had been deprecated for several years. ~cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePublicKey.public_bytes and ~cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePublicKey.from_encoded_point should be used instead.
BACKWARDS INCOMPATIBLE: Support for using MD5 or SHA1 in ~cryptography.x509.CertificateBuilder, other X.509 builders, and PKCS7 has been removed.
BACKWARDS INCOMPATIBLE: Dropped support for macOS 10.10 and 10.11, macOS users must upgrade to 10.12 or newer.
ANNOUNCEMENT: The next version of cryptography (40.0) will change the way we link OpenSSL. This will only impact users who build cryptography from source (i.e., not from a wheel), and specify their own version of OpenSSL. For those users, the CFLAGS, LDFLAGS, INCLUDE, LIB, and CRYPTOGRAPHY_SUPPRESS_LINK_FLAGS environment variables will no longer be respected. Instead, users will need to configure their builds `as documented here`_.
Added support for disabling the legacy provider in OpenSSL 3.0.x.
Added support for disabling RSA key validation checks when loading RSA keys via ~cryptography.hazmat.primitives.serialization.load_pem_private_key, ~cryptography.hazmat.primitives.serialization.load_der_private_key, and ~cryptography.hazmat.primitives.asymmetric.rsa.RSAPrivateNumbers.private_key. This speeds up key loading but is unsafe if you are loading potentially attacker supplied keys.
Significantly improved performance for ~cryptography.hazmat.primitives.ciphers.aead.ChaCha20Poly1305 when repeatedly calling encrypt or decrypt with the same key.
Added support for creating OCSP requests with precomputed hashes using ~cryptography.x509.ocsp.OCSPRequestBuilder.add_certificate_by_hash.
Added support for loading multiple PEM-encoded X.509 certificates from a single input via ~cryptography.x509.load_pem_x509_certificates.
BACKWARDS INCOMPATIBLE: Support for OpenSSL 1.1.0 has been removed. Users on older version of OpenSSL will need to upgrade.
BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.5. The new minimum LibreSSL version is 3.5.0. Going forward our policy is to support versions of LibreSSL that are available in versions of OpenBSD that are still receiving security support.
BACKWARDS INCOMPATIBLE: Removed the encode_point and from_encoded_point methods on EllipticCurvePublicNumbers , which had been deprecated for several years. public_bytes() and from_encoded_point() should be used instead.
BACKWARDS INCOMPATIBLE: Support for using MD5 or SHA1 in CertificateBuilder , other X.509 builders, and PKCS7 has been removed.
BACKWARDS INCOMPATIBLE: Dropped support for macOS 10.10 and 10.11, macOS users must upgrade to 10.12 or newer.
ANNOUNCEMENT: The next version of cryptography (40.0) will change the way we link OpenSSL. This will only impact users who build cryptography from source (i.e., not from a wheel ), and specify their own version of OpenSSL. For those users, the CFLAGS , LDFLAGS , INCLUDE , LIB , and CRYPTOGRAPHY_SUPPRESS_LINK_FLAGS environment variables will no longer be respected. Instead, users will need to configure their builds as documented here .
Added support for disabling the legacy provider in OpenSSL 3.0.x .
Added support for disabling RSA key validation checks when loading RSA keys via load_pem_private_key() , load_der_private_key() , and private_key() . This speeds up key loading but is unsafe if you are loading potentially attacker supplied keys.
Significantly improved performance for ChaCha20Poly1305 when repeatedly calling encrypt or decrypt with the same key.
Added support for creating OCSP requests with precomputed hashes using add_certificate_by_hash() .
Added support for loading multiple PEM-encoded X.509 certificates from a single input via load_pem_x509_certificates() .
Fixed compilation when using LibreSSL 3.6.0.
Fixed compilation when using LibreSSL 3.6.0.
Fixed error when using py2app to build an application with a cryptography dependency.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.0.7, which resolves *CVE-2022-3602* and *CVE-2022-3786*.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.0.7, which resolves CVE-2022-3602 and CVE-2022-3786.
This release was subsequently yanked from PyPI due to a regression in OpenSSL.
Attention!
This release was subsequently yanked from PyPI due to a regression in OpenSSL.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.0.6.
Fixed parsing TLVs in ASN.1 with length greater than 65535 bytes (typically seen in large CRLs).
Fixed parsing TLVs in ASN.1 with length greater than 65535 bytes (typically seen in large CRLs).
Final deprecation of OpenSSL 1.1.0. The next release of cryptography will drop support.
Final deprecation of OpenSSL 1.1.0. The next release of cryptography will drop support.
We no longer ship manylinux2010 wheels. Users should upgrade to the latest pip to ensure this doesn't cause issues downloading wheels on their platform. We now ship manylinux_2_28 wheels for users on new enough platforms.
Updated the minimum supported Rust version (MSRV) to 1.48.0, from 1.41.0. Users with the latest pip will typically get a wheel and not need Rust installed, but check /installation for documentation on installing a newer rustc if required.
~cryptography.fernet.Fernet.decrypt and related methods now accept both str and bytes tokens.
Parsing CertificateSigningRequest restores the behavior of enforcing that the Extension critical field must be correctly encoded DER. See the issue for complete details.
Added two new OpenSSL functions to the bindings to support an upcoming pyOpenSSL release.
When parsing ~cryptography.x509.CertificateRevocationList and ~cryptography.x509.CertificateSigningRequest values, it is now enforced that the version value in the input must be valid according to the rules of 2986 and 5280.
Using MD5 or SHA1 in ~cryptography.x509.CertificateBuilder and other X.509 builders is deprecated and support will be removed in the next version.
Added additional APIs to ~cryptography.x509.certificate_transparency.SignedCertificateTimestamp, including ~cryptography.x509.certificate_transparency.SignedCertificateTimestamp.signature_hash_algorithm, ~cryptography.x509.certificate_transparency.SignedCertificateTimestamp.signature_algorithm, ~cryptography.x509.certificate_transparency.SignedCertificateTimestamp.signature, and ~cryptography.x509.certificate_transparency.SignedCertificateTimestamp.extension_bytes.
Added ~cryptography.x509.Certificate.tbs_precertificate_bytes, allowing users to access the to-be-signed pre-certificate data needed for signed certificate timestamp verification.
~cryptography.hazmat.primitives.kdf.kbkdf.KBKDFHMAC and ~cryptography.hazmat.primitives.kdf.kbkdf.KBKDFCMAC now support ~cryptography.hazmat.primitives.kdf.kbkdf.CounterLocation.MiddleFixed counter location.
Fixed 4514 name parsing to reverse the order of the RDNs according to the section 2.1 of the RFC, affecting method ~cryptography.x509.Name.from_rfc4514_string.
It is now possible to customize some aspects of encryption when serializing private keys, using ~cryptography.hazmat.primitives.serialization.PrivateFormat.encryption_builder.
Removed several legacy symbols from our OpenSSL bindings. Users of pyOpenSSL versions older than 22.0 will need to upgrade.
Added ~cryptography.hazmat.primitives.ciphers.algorithms.AES128 and ~cryptography.hazmat.primitives.ciphers.algorithms.AES256 classes. These classes do not replace ~cryptography.hazmat.primitives.ciphers.algorithms.AES (which allows all AES key lengths), but are intended for applications where developers want to be explicit about key length.
Final deprecation of OpenSSL 1.1.0. The next release of cryptography will drop support.
We no longer ship manylinux2010 wheels. Users should upgrade to the latest pip to ensure this doesn’t cause issues downloading wheels on their platform. We now ship manylinux_2_28 wheels for users on new enough platforms.
Updated the minimum supported Rust version (MSRV) to 1.48.0, from 1.41.0. Users with the latest pip will typically get a wheel and not need Rust installed, but check Installation for documentation on installing a newer rustc if required.
decrypt() and related methods now accept both str and bytes tokens.
Parsing CertificateSigningRequest restores the behavior of enforcing that the Extension critical field must be correctly encoded DER. See the issue for complete details.
Added two new OpenSSL functions to the bindings to support an upcoming pyOpenSSL release.
When parsing CertificateRevocationList and CertificateSigningRequest values, it is now enforced that the version value in the input must be valid according to the rules of RFC 2986 and RFC 5280 .
Using MD5 or SHA1 in CertificateBuilder and other X.509 builders is deprecated and support will be removed in the next version.
Added additional APIs to SignedCertificateTimestamp , including signature_hash_algorithm , signature_algorithm , signature , and extension_bytes .
Added tbs_precertificate_bytes , allowing users to access the to-be-signed pre-certificate data needed for signed certificate timestamp verification.
KBKDFHMAC and KBKDFCMAC now support MiddleFixed counter location.
Fixed RFC 4514 name parsing to reverse the order of the RDNs according to the section 2.1 of the RFC, affecting method from_rfc4514_string() .
It is now possible to customize some aspects of encryption when serializing private keys, using encryption_builder() .
Removed several legacy symbols from our OpenSSL bindings. Users of pyOpenSSL versions older than 22.0 will need to upgrade.
Added AES128 and AES256 classes. These classes do not replace AES (which allows all AES key lengths), but are intended for applications where developers want to be explicit about key length.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.0.5.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.0.5.
This release was subsequently yanked from PyPI due to a regression in OpenSSL.
Attention!
This release was subsequently yanked from PyPI due to a regression in OpenSSL.
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.0.4.
Your coding agent can read these notes before it upgrades. Set up the MCP server →