NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #848 most downloaded on PyPI
TLS (SSL) sockets, key generation, encryption, decryption, signing, verification and KDFs using the OS crypto libraries. Does not require a compiler, and relies on the OS for patching. Works on Windows, OS X and Linux/BSD.
Last release 5 years ago
no release in 18 months
Release timing varies
gaps range from 9 days to 1.8 years
Nearly every release is documented
notes for 24 of 24 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
24 releases · first in 2015
Add first-class support for RSASSA-PSS certificates
asymmetric.load_public_key() via @Arbitrage0Fix running in an environment with a custom OpenSSL install on macOS 10.15
ctype.find_library() no longer
works due to system .dylibs no longer being present on the filesystemEPROTOTYPE error that may be returned when a TLS
connection is terminatedoscrypto-tests sdist on PyPi to work properly to generate a
.whlOne column per quarter.
Allow oscrypto.use_ctypes(), oscrypto.use_openssl() and oscrypto.use_winlegacy() to be called after initialization as long as the configuration does n
oscrypto.use_ctypes(), oscrypto.use_openssl() and
oscrypto.use_winlegacy() to be called after initialization as long as the
configuration does not changeUse versioned libcrypto.dylib and libssl.dylib on macOS Catalina to prevent segfaults
Added oscrypto.load_order(), which returns a list of unicode strings of the names of the fully-qualified module names for all of submodules of the pac
oscrypto.load_order(), which returns a list of unicode strings
of the names of the fully-qualified module names for all of submodules of
the package. The module names are listed in their dependency load order.
This is primarily intended for the sake of implementing hot reloading.oscrypto.backend() will now return "mac" instead of "osx" when running on a Mac and not explicitly configured to use OpenSSL
oscrypto.backend() will now return "mac" instead of "osx" when
running on a Mac and not explicitly configured to use OpenSSLasn1crypto.keys.PrivateKeyInfo().unwrap() is now
asymmetric.PrivateKey().unwrap()asn1crypto.keys.PrivateKeyInfo().public_key is now
asymmetric.PrivateKey().public_key.unwrap()asn1crypto.keys.PrivateKeyInfo().public_key_info is now
asymmetric.PrivateKey().public_key.asn1asn1crypto.keys.PrivateKeyInfo().fingerprint is now
asymmetric.PrivateKey().fingerprintasn1crypto.keys.PublicKeyInfo().unwrap() is now
asymmetric.PublicKey().unwrap()asn1crypto.keys.PublicKeyInfo().fingerprint is now
asymmetric.PublicKey().fingerprintoscrypto.use_ctypes() to avoid CFFI if desiredtls.TLSSocket().port propertytls.TLSSocket()keys.parse_private(), keys.parse_public() and
keys.parse_certificate()tls.TLSSocket().read_until() that would sometimes read
more data from the socket than necessaryutil.pbkdf2() that would cause incorrect output in some
situations when run on Windows XP or with OpenSSL 0.9.8aes_cbc_no_padding_encrypt() so it can be executed when the backend
is OpenSSLSecTrustRef obtained from SSLCopyPeerTrust() on Mac is now
properly releasedwheel, sdist and bdist_egg releases now all include LICENSE,
sdist includes docsoscrypto_tests package to PyPiFixed a bug where trust_list.get_path() would not call the cert_callback when a certificate was exported
trust_list.get_path() would not call the cert_callback
when a certificate was exportedBackwards compatibility break: trust_list.get_path() not longer accepts the parameter map_vendor_oids, and only includes CA certificates that the OS m
trust_list.get_path() not longer accepts
the parameter map_vendor_oids, and only includes CA certificates that
the OS marks as trusted for TLS server authentication. This change was
made due to (at least some versions of) OpenSSL not verifying a server
certificate if the CA bundle includes a TRUSTED CERTIFICATE entry,
which is how the trust information was exported. Since trust information
can no longer be exported to disk, the list of certificates must be
filtered, and since the intent of this function was always to provide a
list of CA certs for use by OpenSSL when creating TLS connection, this
change in functionality is in line with the original intent.asymmetric.rsa_pkcs1v15_verify() and asymmetric.rsa_rss_verify() will
now raise a SignatureError when there is a key size mismatch.trust_list.get_path() and trust_list.get_list() now accept a parameter cert_callback, which is a callback that will be called once for each certificat
trust_list.get_path() and trust_list.get_list() now accept a parameter
cert_callback, which is a callback that will be called once for each
certificate in the trust store. If the certificate will not be exported, a
reason will be provided.oscrypto.version for version introspection without side-effectsasn1crypto.algos.DSASignature instead of self-contained ASN.1
definitionWork around an issue on OS X where SecureTransport would try to read non-TLS data as TLS records, causing hangs with tls.TLSSocket()
tls.TLSSocket()Handle errSecInvalidTrustSettings errors on macOS exporting trust roots
errSecInvalidTrustSettings errors on macOS exporting trust rootsKeyError on macOS when exporting trust roots and trust settings
are present for certificates not in the listExpose LibraryNotFoundError via errors.LibraryNotFoundError
LibraryNotFoundError via errors.LibraryNotFoundErrorAdded support for OpenSSL 1.1.0
asymmetric.PublicKey, asymmetric.PrivateKey and asymmetric.Certificate
objectserrSecAuthFailed error that occurs when calling
asymmetric.generate_*() functions on OS X in some virtualenvsAllow cffi files to be removed from source tree when embedding
cffi files to be removed from source tree when embeddingUpdated asn1crypto dependency to 0.18.1.
0.18.1.Backwards compatibility break: trust_list.get_list() now returns a list of 3-element tuples containing the certificate byte string, a set of trust OID
trust_list.get_list() now returns a list of
3-element tuples containing the certificate byte string, a set of trust OIDs
and a set of reject OIDs. Previously it returned a list of certificate byte
strings.trust_list now makes OS trust information OIDs available via the
trust_list.get_list() function, and writes OpenSSL-compatible trust
information to the CA certs file when calling trust_info.get_path() on
Windows and OS X.Added asymmetric.generate_dh_parameters() and asymmetric.dump_dh_parameters()
asymmetric.generate_dh_parameters() and
asymmetric.dump_dh_parameters()tls.TLSSocket on Windowsextra_trust_roots parameter of tls.TLSSessionFixed trust_list to work with new Security.framework behavior on OS X 10.11 El Capitan
trust_list to work with new Security.framework behavior on OS X
10.11 El Capitantls.TLSSocket() on Windows when using TLSv1.2
and the server negotiated using a DHE_RSA key exchangesocket.recv()asymmetric.dump_private_key()Fixed a bug where asymmetric.generate_pair() would raise an exception on OS X when the system Python was used to create a virtualenv
asymmetric.generate_pair() would raise an exception on
OS X when the system Python was used to create a virtualenvtls.TLSSocket() now has a default connect, read and write timeout of 10 seconds
tls.TLSSocket() now has a default connect, read and write timeout of 10
secondsmanual_validation keyword param for tls.TLSSession() on
all three platformsasymmetric.PublicKey.self_signed that would always force
signature verificationtls.TLSSocket() on OS X now respects KeyboardInterrupt while in a read
or write callbacktrust_list.get_list() on Windows now returns a de-duplicated listImproved handling of signature errors to always raise errors.SignatureError
errors.SignatureErrortrust_list.get_list() on Windows not returning
certificates that were valid for all usesBackwards compatibility break: trust_list.get_list() now returns a list of asn1crypto.x509.Certificate objects instead of a list of byte strings
trust_list.get_list() now returns a list of
asn1crypto.x509.Certificate objects instead of a list of byte stringstrust_list.get_list() now returns a copy of the list to prevent accidental
modification of the listtls.TLSSocket.hostnameFixed Python 2.6 support on Windows and Linux
FILETIME struct with Python 2 on Windows to a
datetime objectextra_trust_roots in a
tls.TLSSessionHandles specific weak DH keys error code in newer versions of OpenSSL
__str__() and __unicode__() to TLS exceptionsYour coding agent can read these notes before it upgrades. Set up the MCP server →