Team Ai
Apppublic

parthtamu/rag-code-assistant

sourceHugging Faceupdated 7mo agoView on Hugging Face
0likes
ssl.html3771 linesDownload Raw Back to docs
1<!DOCTYPE html>2 3<html lang="en" data-content_root="../">4  <head>5    <meta charset="utf-8" />6    <meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />7<meta property="og:title" content="ssl — TLS/SSL wrapper for socket objects" />8<meta property="og:type" content="website" />9<meta property="og:url" content="https://docs.python.org/3/library/ssl.html" />10<meta property="og:site_name" content="Python documentation" />11<meta property="og:description" content="Source code: Lib/ssl.py This module provides access to Transport Layer Security (often known as “Secure Sockets Layer”) encryption and peer authentication facilities for network sockets, both clien..." />12<meta property="og:image:width" content="1146" />13<meta property="og:image:height" content="600" />14<meta property="og:image" content="https://docs.python.org/3.15/_images/social_previews/summary_library_ssl_fab19422.png" />15<meta property="og:image:alt" content="Source code: Lib/ssl.py This module provides access to Transport Layer Security (often known as “Secure Sockets Layer”) encryption and peer authentication facilities for network sockets, both clien..." />16<meta name="description" content="Source code: Lib/ssl.py This module provides access to Transport Layer Security (often known as “Secure Sockets Layer”) encryption and peer authentication facilities for network sockets, both clien..." />17<meta name="twitter:card" content="summary_large_image" />18<meta name="theme-color" content="#3776ab">19 20    <title>ssl — TLS/SSL wrapper for socket objects &#8212; Python 3.15.0a6 documentation</title><meta name="viewport" content="width=device-width, initial-scale=1.0">21    22    <link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=b86133f3" />23    <link rel="stylesheet" type="text/css" href="../_static/classic.css?v=234b1a7c" />24    <link rel="stylesheet" type="text/css" href="../_static/pydoctheme.css?v=89a2f22a" />25    <link rel="stylesheet" type="text/css" href="../_static/profiling-sampling-visualization.css?v=0c2600ae" />26    <link id="pygments_dark_css" media="(prefers-color-scheme: dark)" rel="stylesheet" type="text/css" href="../_static/pygments_dark.css?v=5349f25f" />27    28    <script src="../_static/documentation_options.js?v=6b7c9ff5"></script>29    <script src="../_static/doctools.js?v=9bcbadda"></script>30    <script src="../_static/sphinx_highlight.js?v=dc90522c"></script>31    <script src="../_static/profiling-sampling-visualization.js?v=9811ed04"></script>32    33    <script src="../_static/sidebar.js"></script>34    35    <link rel="search" type="application/opensearchdescription+xml"36          title="Search within Python 3.15.0a6 documentation"37          href="../_static/opensearch.xml"/>38    <link rel="author" title="About these documents" href="../about.html" />39    <link rel="index" title="Index" href="../genindex.html" />40    <link rel="search" title="Search" href="../search.html" />41    <link rel="copyright" title="Copyright" href="../copyright.html" />42    <link rel="next" title="select — Waiting for I/O completion" href="select.html" />43    <link rel="prev" title="socket — Low-level networking interface" href="socket.html" />44    45      46      <script defer file-types="bz2,epub,zip" data-domain="docs.python.org" src="https://analytics.python.org/js/script.file-downloads.outbound-links.js"></script>47      48      <link rel="canonical" href="https://docs.python.org/3/library/ssl.html">49      50    51 52    53    <style>54      @media only screen {55        table.full-width-table {56            width: 100%;57        }58      }59    </style>60<link rel="stylesheet" href="../_static/pydoctheme_dark.css" media="(prefers-color-scheme: dark)" id="pydoctheme_dark_css">61    <link rel="shortcut icon" type="image/png" href="../_static/py.svg">62            <script type="text/javascript" src="../_static/copybutton.js"></script>63            <script type="text/javascript" src="../_static/menu.js"></script>64            <script type="text/javascript" src="../_static/search-focus.js"></script>65            <script type="text/javascript" src="../_static/themetoggle.js"></script> 66            <script type="text/javascript" src="../_static/rtd_switcher.js"></script>67            <meta name="readthedocs-addons-api-version" content="1">68 69  </head>70<body>71<div class="mobile-nav">72    <input type="checkbox" id="menuToggler" class="toggler__input" aria-controls="navigation"73           aria-pressed="false" aria-expanded="false" role="button" aria-label="Menu">74    <nav class="nav-content" role="navigation">75        <label for="menuToggler" class="toggler__label">76            <span></span>77        </label>78        <span class="nav-items-wrapper">79            <a href="https://www.python.org/" class="nav-logo">80                <img src="../_static/py.svg" alt="Python logo">81            </a>82            <span class="version_switcher_placeholder"></span>83            <form role="search" class="search" action="../search.html" method="get">84                <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" class="search-icon">85                    <path fill-rule="nonzero" fill="currentColor" d="M15.5 14h-.79l-.28-.27a6.5 6.5 0 001.48-5.34c-.47-2.78-2.79-5-5.59-5.34a6.505 6.505 0 00-7.27 7.27c.34 2.8 2.56 5.12 5.34 5.59a6.5 6.5 0 005.34-1.48l.27.28v.79l4.25 4.25c.41.41 1.08.41 1.49 0 .41-.41.41-1.08 0-1.49L15.5 14zm-6 0C7.01 14 5 11.99 5 9.5S7.01 5 9.5 5 14 7.01 14 9.5 11.99 14 9.5 14z"></path>86                </svg>87                <input placeholder="Quick search" aria-label="Quick search" type="search" name="q">88                <input type="submit" value="Go">89            </form>90        </span>91    </nav>92    <div class="menu-wrapper">93        <nav class="menu" role="navigation" aria-label="main navigation">94            <div class="language_switcher_placeholder"></div>95            96<label class="theme-selector-label">97    Theme98    <select class="theme-selector" oninput="activateTheme(this.value)">99        <option value="auto" selected>Auto</option>100        <option value="light">Light</option>101        <option value="dark">Dark</option>102    </select>103</label>104  <div>105    <h3><a href="../contents.html">Table of Contents</a></h3>106    <ul>107<li><a class="reference internal" href="#"><code class="xref py py-mod docutils literal notranslate"><span class="pre">ssl</span></code> — TLS/SSL wrapper for socket objects</a><ul>108<li><a class="reference internal" href="#functions-constants-and-exceptions">Functions, Constants, and Exceptions</a><ul>109<li><a class="reference internal" href="#socket-creation">Socket creation</a></li>110<li><a class="reference internal" href="#context-creation">Context creation</a></li>111<li><a class="reference internal" href="#signature-algorithms">Signature algorithms</a></li>112<li><a class="reference internal" href="#exceptions">Exceptions</a></li>113<li><a class="reference internal" href="#random-generation">Random generation</a></li>114<li><a class="reference internal" href="#certificate-handling">Certificate handling</a></li>115<li><a class="reference internal" href="#constants">Constants</a></li>116</ul>117</li>118<li><a class="reference internal" href="#ssl-sockets">SSL Sockets</a></li>119<li><a class="reference internal" href="#ssl-contexts">SSL Contexts</a></li>120<li><a class="reference internal" href="#certificates">Certificates</a><ul>121<li><a class="reference internal" href="#certificate-chains">Certificate chains</a></li>122<li><a class="reference internal" href="#ca-certificates">CA certificates</a></li>123<li><a class="reference internal" href="#combined-key-and-certificate">Combined key and certificate</a></li>124<li><a class="reference internal" href="#self-signed-certificates">Self-signed certificates</a></li>125</ul>126</li>127<li><a class="reference internal" href="#examples">Examples</a><ul>128<li><a class="reference internal" href="#testing-for-ssl-support">Testing for SSL support</a></li>129<li><a class="reference internal" href="#client-side-operation">Client-side operation</a></li>130<li><a class="reference internal" href="#server-side-operation">Server-side operation</a></li>131</ul>132</li>133<li><a class="reference internal" href="#notes-on-non-blocking-sockets">Notes on non-blocking sockets</a></li>134<li><a class="reference internal" href="#memory-bio-support">Memory BIO Support</a></li>135<li><a class="reference internal" href="#ssl-session">SSL session</a></li>136<li><a class="reference internal" href="#security-considerations">Security considerations</a><ul>137<li><a class="reference internal" href="#best-defaults">Best defaults</a></li>138<li><a class="reference internal" href="#manual-settings">Manual settings</a><ul>139<li><a class="reference internal" href="#verifying-certificates">Verifying certificates</a></li>140<li><a class="reference internal" href="#protocol-versions">Protocol versions</a></li>141<li><a class="reference internal" href="#cipher-selection">Cipher selection</a></li>142</ul>143</li>144<li><a class="reference internal" href="#multi-processing">Multi-processing</a></li>145</ul>146</li>147<li><a class="reference internal" href="#tls-1-3">TLS 1.3</a></li>148</ul>149</li>150</ul>151 152  </div>153  <div>154    <h4>Previous topic</h4>155    <p class="topless"><a href="socket.html"156                          title="previous chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">socket</span></code> — Low-level networking interface</a></p>157  </div>158  <div>159    <h4>Next topic</h4>160    <p class="topless"><a href="select.html"161                          title="next chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">select</span></code> — Waiting for I/O completion</a></p>162  </div>163  <script>164    document.addEventListener('DOMContentLoaded', () => {165        const title = document.querySelector('meta[property="og:title"]').content;166        const elements = document.querySelectorAll('.improvepage');167        const pageurl = window.location.href.split('?')[0];168        elements.forEach(element => {169            const url = new URL(element.href.split('?')[0].replace("-nojs", ""));170            url.searchParams.set('pagetitle', title);171            url.searchParams.set('pageurl', pageurl);172            url.searchParams.set('pagesource', "library/ssl.rst");173            element.href = url.toString();174        });175    });176  </script>177  <div role="note" aria-label="source link">178    <h3>This page</h3>179    <ul class="this-page-menu">180      <li><a href="../bugs.html">Report a bug</a></li>181      <li><a class="improvepage" href="../improve-page-nojs.html">Improve this page</a></li>182      <li>183        <a href="https://github.com/python/cpython/blob/main/Doc/library/ssl.rst?plain=1"184            rel="nofollow">Show source185        </a>186      </li>187      188    </ul>189  </div>190        </nav>191    </div>192</div>193 194  195    <div class="related" role="navigation" aria-label="Related">196      <h3>Navigation</h3>197      <ul>198        <li class="right" style="margin-right: 10px">199          <a href="../genindex.html" title="General Index"200             accesskey="I">index</a></li>201        <li class="right" >202          <a href="../py-modindex.html" title="Python Module Index"203             >modules</a> |</li>204        <li class="right" >205          <a href="select.html" title="select — Waiting for I/O completion"206             accesskey="N">next</a> |</li>207        <li class="right" >208          <a href="socket.html" title="socket — Low-level networking interface"209             accesskey="P">previous</a> |</li>210 211          <li><img src="../_static/py.svg" alt="Python logo" style="vertical-align: middle; margin-top: -1px"></li>212          <li><a href="https://www.python.org/">Python</a> &#187;</li>213          <li class="switchers">214            <div class="language_switcher_placeholder"></div>215            <div class="version_switcher_placeholder"></div>216          </li>217          <li>218              219          </li>220    <li id="cpython-language-and-version">221      <a href="../index.html">3.15.0a6 Documentation</a> &#187;222    </li>223 224          <li class="nav-item nav-item-1"><a href="index.html" >The Python Standard Library</a> &#187;</li>225          <li class="nav-item nav-item-2"><a href="ipc.html" accesskey="U">Networking and Interprocess Communication</a> &#187;</li>226        <li class="nav-item nav-item-this"><a href=""><code class="xref py py-mod docutils literal notranslate"><span class="pre">ssl</span></code> — TLS/SSL wrapper for socket objects</a></li>227                <li class="right">228                    229 230    <div class="inline-search" role="search">231        <form class="inline-search" action="../search.html" method="get">232          <input placeholder="Quick search" aria-label="Quick search" type="search" name="q" id="search-box">233          <input type="submit" value="Go">234        </form>235    </div>236                     |237                </li>238            <li class="right">239<label class="theme-selector-label">240    Theme241    <select class="theme-selector" oninput="activateTheme(this.value)">242        <option value="auto" selected>Auto</option>243        <option value="light">Light</option>244        <option value="dark">Dark</option>245    </select>246</label> |</li>247            248      </ul>249    </div>    250 251    <div class="document">252      <div class="documentwrapper">253        <div class="bodywrapper">254          <div class="body" role="main">255            256  <section id="module-ssl">257<span id="ssl-tls-ssl-wrapper-for-socket-objects"></span><h1><code class="xref py py-mod docutils literal notranslate"><span class="pre">ssl</span></code> — TLS/SSL wrapper for socket objects<a class="headerlink" href="#module-ssl" title="Link to this heading">¶</a></h1>258<p><strong>Source code:</strong> <a class="extlink-source reference external" href="https://github.com/python/cpython/tree/main/Lib/ssl.py">Lib/ssl.py</a></p>259<span id="index-0"></span><hr class="docutils" id="index-1" />260<p>This module provides access to Transport Layer Security (often known as “Secure261Sockets Layer”) encryption and peer authentication facilities for network262sockets, both client-side and server-side.  This module uses the OpenSSL263library.</p>264<p>This is an <a class="reference internal" href="../glossary.html#term-optional-module"><span class="xref std std-term">optional module</span></a>.265If it is missing from your copy of CPython,266look for documentation from your distributor (that is,267whoever provided Python to you).268If you are the distributor, see <a class="reference internal" href="../using/configure.html#optional-module-requirements"><span class="std std-ref">Requirements for optional modules</span></a>.</p>269<div class="admonition note">270<p class="admonition-title">Note</p>271<p>Some behavior may be platform dependent, since calls are made to the272operating system socket APIs.  The installed version of OpenSSL may also273cause variations in behavior. For example, TLSv1.3 comes with OpenSSL version2741.1.1.</p>275</div>276<div class="admonition warning">277<p class="admonition-title">Warning</p>278<p>Don’t use this module without reading the <a class="reference internal" href="#ssl-security"><span class="std std-ref">Security considerations</span></a>.  Doing so279may lead to a false sense of security, as the default settings of the280ssl module are not necessarily appropriate for your application.</p>281</div>282<div class="availability docutils container">283<p><a class="reference internal" href="intro.html#availability"><span class="std std-ref">Availability</span></a>: not WASI.</p>284<p>This module does not work or is not available on WebAssembly. See285<a class="reference internal" href="intro.html#wasm-availability"><span class="std std-ref">WebAssembly platforms</span></a> for more information.</p>286</div>287<p>This section documents the objects and functions in the <code class="docutils literal notranslate"><span class="pre">ssl</span></code> module; for more288general information about TLS, SSL, and certificates, the reader is referred to289the documents in the “See Also” section at the bottom.</p>290<p>This module provides a class, <a class="reference internal" href="#ssl.SSLSocket" title="ssl.SSLSocket"><code class="xref py py-class docutils literal notranslate"><span class="pre">ssl.SSLSocket</span></code></a>, which is derived from the291<a class="reference internal" href="socket.html#socket.socket" title="socket.socket"><code class="xref py py-class docutils literal notranslate"><span class="pre">socket.socket</span></code></a> type, and provides a socket-like wrapper that also292encrypts and decrypts the data going over the socket with SSL.  It supports293additional methods such as <code class="xref py py-meth docutils literal notranslate"><span class="pre">getpeercert()</span></code>, which retrieves the294certificate of the other side of the connection, <code class="xref py py-meth docutils literal notranslate"><span class="pre">cipher()</span></code>, which295retrieves the cipher being used for the secure connection or296<code class="xref py py-meth docutils literal notranslate"><span class="pre">get_verified_chain()</span></code>, <code class="xref py py-meth docutils literal notranslate"><span class="pre">get_unverified_chain()</span></code> which retrieves297certificate chain.</p>298<p>For more sophisticated applications, the <a class="reference internal" href="#ssl.SSLContext" title="ssl.SSLContext"><code class="xref py py-class docutils literal notranslate"><span class="pre">ssl.SSLContext</span></code></a> class299helps manage settings and certificates, which can then be inherited300by SSL sockets created through the <a class="reference internal" href="#ssl.SSLContext.wrap_socket" title="ssl.SSLContext.wrap_socket"><code class="xref py py-meth docutils literal notranslate"><span class="pre">SSLContext.wrap_socket()</span></code></a> method.</p>301<div class="versionchanged">302<p><span class="versionmodified changed">Changed in version 3.5.3: </span>Updated to support linking with OpenSSL 1.1.0</p>303</div>304<div class="versionchanged">305<p><span class="versionmodified changed">Changed in version 3.6: </span>OpenSSL 0.9.8, 1.0.0 and 1.0.1 are deprecated and no longer supported.306In the future the ssl module will require at least OpenSSL 1.0.2 or3071.1.0.</p>308</div>309<div class="versionchanged">310<p><span class="versionmodified changed">Changed in version 3.10: </span><span class="target" id="index-2"></span><a class="pep reference external" href="https://peps.python.org/pep-0644/"><strong>PEP 644</strong></a> has been implemented. The ssl module requires OpenSSL 1.1.1311or newer.</p>312<p>Use of deprecated constants and functions result in deprecation warnings.</p>313</div>314<section id="functions-constants-and-exceptions">315<h2>Functions, Constants, and Exceptions<a class="headerlink" href="#functions-constants-and-exceptions" title="Link to this heading">¶</a></h2>316<section id="socket-creation">317<h3>Socket creation<a class="headerlink" href="#socket-creation" title="Link to this heading">¶</a></h3>318<p>Instances of <a class="reference internal" href="#ssl.SSLSocket" title="ssl.SSLSocket"><code class="xref py py-class docutils literal notranslate"><span class="pre">SSLSocket</span></code></a> must be created using the319<a class="reference internal" href="#ssl.SSLContext.wrap_socket" title="ssl.SSLContext.wrap_socket"><code class="xref py py-meth docutils literal notranslate"><span class="pre">SSLContext.wrap_socket()</span></code></a> method. The helper function320<a class="reference internal" href="#ssl.create_default_context" title="ssl.create_default_context"><code class="xref py py-func docutils literal notranslate"><span class="pre">create_default_context()</span></code></a> returns a new context with secure default321settings.</p>322<p>Client socket example with default context and IPv4/IPv6 dual stack:</p>323<div class="highlight-python3 notranslate"><div class="highlight"><pre><span></span><span class="kn">import</span><span class="w"> </span><span class="nn">socket</span>324<span class="kn">import</span><span class="w"> </span><span class="nn">ssl</span>325 326<span class="n">hostname</span> <span class="o">=</span> <span class="s1">&#39;www.python.org&#39;</span>327<span class="n">context</span> <span class="o">=</span> <span class="n">ssl</span><span class="o">.</span><span class="n">create_default_context</span><span class="p">()</span>328 329<span class="k">with</span> <span class="n">socket</span><span class="o">.</span><span class="n">create_connection</span><span class="p">((</span><span class="n">hostname</span><span class="p">,</span> <span class="mi">443</span><span class="p">))</span> <span class="k">as</span> <span class="n">sock</span><span class="p">:</span>330    <span class="k">with</span> <span class="n">context</span><span class="o">.</span><span class="n">wrap_socket</span><span class="p">(</span><span class="n">sock</span><span class="p">,</span> <span class="n">server_hostname</span><span class="o">=</span><span class="n">hostname</span><span class="p">)</span> <span class="k">as</span> <span class="n">ssock</span><span class="p">:</span>331        <span class="nb">print</span><span class="p">(</span><span class="n">ssock</span><span class="o">.</span><span class="n">version</span><span class="p">())</span>332</pre></div>333</div>334<p>Client socket example with custom context and IPv4:</p>335<div class="highlight-python3 notranslate"><div class="highlight"><pre><span></span><span class="n">hostname</span> <span class="o">=</span> <span class="s1">&#39;www.python.org&#39;</span>336<span class="c1"># PROTOCOL_TLS_CLIENT requires valid cert chain and hostname</span>337<span class="n">context</span> <span class="o">=</span> <span class="n">ssl</span><span class="o">.</span><span class="n">SSLContext</span><span class="p">(</span><span class="n">ssl</span><span class="o">.</span><span class="n">PROTOCOL_TLS_CLIENT</span><span class="p">)</span>338<span class="n">context</span><span class="o">.</span><span class="n">load_verify_locations</span><span class="p">(</span><span class="s1">&#39;path/to/cabundle.pem&#39;</span><span class="p">)</span>339 340<span class="k">with</span> <span class="n">socket</span><span class="o">.</span><span class="n">socket</span><span class="p">(</span><span class="n">socket</span><span class="o">.</span><span class="n">AF_INET</span><span class="p">,</span> <span class="n">socket</span><span class="o">.</span><span class="n">SOCK_STREAM</span><span class="p">,</span> <span class="mi">0</span><span class="p">)</span> <span class="k">as</span> <span class="n">sock</span><span class="p">:</span>341    <span class="k">with</span> <span class="n">context</span><span class="o">.</span><span class="n">wrap_socket</span><span class="p">(</span><span class="n">sock</span><span class="p">,</span> <span class="n">server_hostname</span><span class="o">=</span><span class="n">hostname</span><span class="p">)</span> <span class="k">as</span> <span class="n">ssock</span><span class="p">:</span>342        <span class="nb">print</span><span class="p">(</span><span class="n">ssock</span><span class="o">.</span><span class="n">version</span><span class="p">())</span>343</pre></div>344</div>345<p>Server socket example listening on localhost IPv4:</p>346<div class="highlight-python3 notranslate"><div class="highlight"><pre><span></span><span class="n">context</span> <span class="o">=</span> <span class="n">ssl</span><span class="o">.</span><span class="n">SSLContext</span><span class="p">(</span><span class="n">ssl</span><span class="o">.</span><span class="n">PROTOCOL_TLS_SERVER</span><span class="p">)</span>347<span class="n">context</span><span class="o">.</span><span class="n">load_cert_chain</span><span class="p">(</span><span class="s1">&#39;/path/to/certchain.pem&#39;</span><span class="p">,</span> <span class="s1">&#39;/path/to/private.key&#39;</span><span class="p">)</span>348 349<span class="k">with</span> <span class="n">socket</span><span class="o">.</span><span class="n">socket</span><span class="p">(</span><span class="n">socket</span><span class="o">.</span><span class="n">AF_INET</span><span class="p">,</span> <span class="n">socket</span><span class="o">.</span><span class="n">SOCK_STREAM</span><span class="p">,</span> <span class="mi">0</span><span class="p">)</span> <span class="k">as</span> <span class="n">sock</span><span class="p">:</span>350    <span class="n">sock</span><span class="o">.</span><span class="n">bind</span><span class="p">((</span><span class="s1">&#39;127.0.0.1&#39;</span><span class="p">,</span> <span class="mi">8443</span><span class="p">))</span>351    <span class="n">sock</span><span class="o">.</span><span class="n">listen</span><span class="p">(</span><span class="mi">5</span><span class="p">)</span>352    <span class="k">with</span> <span class="n">context</span><span class="o">.</span><span class="n">wrap_socket</span><span class="p">(</span><span class="n">sock</span><span class="p">,</span> <span class="n">server_side</span><span class="o">=</span><span class="kc">True</span><span class="p">)</span> <span class="k">as</span> <span class="n">ssock</span><span class="p">:</span>353        <span class="n">conn</span><span class="p">,</span> <span class="n">addr</span> <span class="o">=</span> <span class="n">ssock</span><span class="o">.</span><span class="n">accept</span><span class="p">()</span>354        <span class="o">...</span>355</pre></div>356</div>357</section>358<section id="context-creation">359<h3>Context creation<a class="headerlink" href="#context-creation" title="Link to this heading">¶</a></h3>360<p>A convenience function helps create <a class="reference internal" href="#ssl.SSLContext" title="ssl.SSLContext"><code class="xref py py-class docutils literal notranslate"><span class="pre">SSLContext</span></code></a> objects for common361purposes.</p>362<dl class="py function">363<dt class="sig sig-object py" id="ssl.create_default_context">364<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">create_default_context</span></span><span class="sig-paren">(</span><em class="sig-param"><span class="n"><span class="pre">purpose</span></span><span class="o"><span class="pre">=</span></span><span class="default_value"><span class="pre">Purpose.SERVER_AUTH</span></span></em>, <em class="sig-param"><span class="keyword-only-separator o"><abbr title="Keyword-only parameters separator (PEP 3102)"><span class="pre">*</span></abbr></span></em>, <em class="sig-param"><span class="n"><span class="pre">cafile</span></span><span class="o"><span class="pre">=</span></span><span class="default_value"><span class="pre">None</span></span></em>, <em class="sig-param"><span class="n"><span class="pre">capath</span></span><span class="o"><span class="pre">=</span></span><span class="default_value"><span class="pre">None</span></span></em>, <em class="sig-param"><span class="n"><span class="pre">cadata</span></span><span class="o"><span class="pre">=</span></span><span class="default_value"><span class="pre">None</span></span></em><span class="sig-paren">)</span><a class="headerlink" href="#ssl.create_default_context" title="Link to this definition">¶</a></dt>365<dd><p>Return a new <a class="reference internal" href="#ssl.SSLContext" title="ssl.SSLContext"><code class="xref py py-class docutils literal notranslate"><span class="pre">SSLContext</span></code></a> object with default settings for366the given <em>purpose</em>.  The settings are chosen by the <code class="xref py py-mod docutils literal notranslate"><span class="pre">ssl</span></code> module,367and usually represent a higher security level than when calling the368<code class="xref py py-class docutils literal notranslate"><span class="pre">SSLContext</span></code> constructor directly.</p>369<p><em>cafile</em>, <em>capath</em>, <em>cadata</em> represent optional CA certificates to370trust for certificate verification, as in371<a class="reference internal" href="#ssl.SSLContext.load_verify_locations" title="ssl.SSLContext.load_verify_locations"><code class="xref py py-meth docutils literal notranslate"><span class="pre">SSLContext.load_verify_locations()</span></code></a>.  If all three are372<a class="reference internal" href="constants.html#None" title="None"><code class="xref py py-const docutils literal notranslate"><span class="pre">None</span></code></a>, this function can choose to trust the system’s default373CA certificates instead.</p>374<p>The settings are: <a class="reference internal" href="#ssl.PROTOCOL_TLS_CLIENT" title="ssl.PROTOCOL_TLS_CLIENT"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS_CLIENT</span></code></a> or375<a class="reference internal" href="#ssl.PROTOCOL_TLS_SERVER" title="ssl.PROTOCOL_TLS_SERVER"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS_SERVER</span></code></a>, <a class="reference internal" href="#ssl.OP_NO_SSLv2" title="ssl.OP_NO_SSLv2"><code class="xref py py-data docutils literal notranslate"><span class="pre">OP_NO_SSLv2</span></code></a>, and <a class="reference internal" href="#ssl.OP_NO_SSLv3" title="ssl.OP_NO_SSLv3"><code class="xref py py-data docutils literal notranslate"><span class="pre">OP_NO_SSLv3</span></code></a>376with high encryption cipher suites without RC4 and377without unauthenticated cipher suites. Passing <a class="reference internal" href="#ssl.Purpose.SERVER_AUTH" title="ssl.Purpose.SERVER_AUTH"><code class="xref py py-const docutils literal notranslate"><span class="pre">SERVER_AUTH</span></code></a>378as <em>purpose</em> sets <a class="reference internal" href="#ssl.SSLContext.verify_mode" title="ssl.SSLContext.verify_mode"><code class="xref py py-data docutils literal notranslate"><span class="pre">verify_mode</span></code></a> to <a class="reference internal" href="#ssl.CERT_REQUIRED" title="ssl.CERT_REQUIRED"><code class="xref py py-data docutils literal notranslate"><span class="pre">CERT_REQUIRED</span></code></a>379and either loads CA certificates (when at least one of <em>cafile</em>, <em>capath</em> or380<em>cadata</em> is given) or uses <a class="reference internal" href="#ssl.SSLContext.load_default_certs" title="ssl.SSLContext.load_default_certs"><code class="xref py py-meth docutils literal notranslate"><span class="pre">SSLContext.load_default_certs()</span></code></a> to load381default CA certificates.</p>382<p>When <a class="reference internal" href="#ssl.SSLContext.keylog_filename" title="ssl.SSLContext.keylog_filename"><code class="xref py py-attr docutils literal notranslate"><span class="pre">keylog_filename</span></code></a> is supported and the environment383variable <span class="target" id="index-3"></span><code class="xref std std-envvar docutils literal notranslate"><span class="pre">SSLKEYLOGFILE</span></code> is set, <code class="xref py py-func docutils literal notranslate"><span class="pre">create_default_context()</span></code>384enables key logging.</p>385<p>The default settings for this context include386<a class="reference internal" href="#ssl.VERIFY_X509_PARTIAL_CHAIN" title="ssl.VERIFY_X509_PARTIAL_CHAIN"><code class="xref py py-data docutils literal notranslate"><span class="pre">VERIFY_X509_PARTIAL_CHAIN</span></code></a> and <a class="reference internal" href="#ssl.VERIFY_X509_STRICT" title="ssl.VERIFY_X509_STRICT"><code class="xref py py-data docutils literal notranslate"><span class="pre">VERIFY_X509_STRICT</span></code></a>.387These make the underlying OpenSSL implementation behave more like388a conforming implementation of <span class="target" id="index-4"></span><a class="rfc reference external" href="https://datatracker.ietf.org/doc/html/rfc5280.html"><strong>RFC 5280</strong></a>, in exchange for a small389amount of incompatibility with older X.509 certificates.</p>390<div class="admonition note">391<p class="admonition-title">Note</p>392<p>The protocol, options, cipher and other settings may change to more393restrictive values anytime without prior deprecation.  The values394represent a fair balance between compatibility and security.</p>395<p>If your application needs specific settings, you should create a396<a class="reference internal" href="#ssl.SSLContext" title="ssl.SSLContext"><code class="xref py py-class docutils literal notranslate"><span class="pre">SSLContext</span></code></a> and apply the settings yourself.</p>397</div>398<div class="admonition note">399<p class="admonition-title">Note</p>400<p>If you find that when certain older clients or servers attempt to connect401with a <a class="reference internal" href="#ssl.SSLContext" title="ssl.SSLContext"><code class="xref py py-class docutils literal notranslate"><span class="pre">SSLContext</span></code></a> created by this function that they get an error402stating “Protocol or cipher suite mismatch”, it may be that they only403support SSL3.0 which this function excludes using the404<a class="reference internal" href="#ssl.OP_NO_SSLv3" title="ssl.OP_NO_SSLv3"><code class="xref py py-data docutils literal notranslate"><span class="pre">OP_NO_SSLv3</span></code></a>. SSL3.0 is widely considered to be <a class="reference external" href="https://en.wikipedia.org/wiki/POODLE">completely broken</a>. If you still wish to continue to405use this function but still allow SSL 3.0 connections you can re-enable406them using:</p>407<div class="highlight-python3 notranslate"><div class="highlight"><pre><span></span><span class="n">ctx</span> <span class="o">=</span> <span class="n">ssl</span><span class="o">.</span><span class="n">create_default_context</span><span class="p">(</span><span class="n">Purpose</span><span class="o">.</span><span class="n">CLIENT_AUTH</span><span class="p">)</span>408<span class="n">ctx</span><span class="o">.</span><span class="n">options</span> <span class="o">&amp;=</span> <span class="o">~</span><span class="n">ssl</span><span class="o">.</span><span class="n">OP_NO_SSLv3</span>409</pre></div>410</div>411</div>412<div class="admonition note">413<p class="admonition-title">Note</p>414<p>This context enables <a class="reference internal" href="#ssl.VERIFY_X509_STRICT" title="ssl.VERIFY_X509_STRICT"><code class="xref py py-data docutils literal notranslate"><span class="pre">VERIFY_X509_STRICT</span></code></a> by default, which415may reject pre-<span class="target" id="index-5"></span><a class="rfc reference external" href="https://datatracker.ietf.org/doc/html/rfc5280.html"><strong>RFC 5280</strong></a> or malformed certificates that the416underlying OpenSSL implementation otherwise would accept. While disabling417this is not recommended, you can do so using:</p>418<div class="highlight-python3 notranslate"><div class="highlight"><pre><span></span><span class="n">ctx</span> <span class="o">=</span> <span class="n">ssl</span><span class="o">.</span><span class="n">create_default_context</span><span class="p">()</span>419<span class="n">ctx</span><span class="o">.</span><span class="n">verify_flags</span> <span class="o">&amp;=</span> <span class="o">~</span><span class="n">ssl</span><span class="o">.</span><span class="n">VERIFY_X509_STRICT</span>420</pre></div>421</div>422</div>423<div class="versionadded">424<p><span class="versionmodified added">Added in version 3.4.</span></p>425</div>426<div class="versionchanged">427<p><span class="versionmodified changed">Changed in version 3.4.4: </span>RC4 was dropped from the default cipher string.</p>428</div>429<div class="versionchanged">430<p><span class="versionmodified changed">Changed in version 3.6: </span>ChaCha20/Poly1305 was added to the default cipher string.</p>431<p>3DES was dropped from the default cipher string.</p>432</div>433<div class="versionchanged">434<p><span class="versionmodified changed">Changed in version 3.8: </span>Support for key logging to <span class="target" id="index-6"></span><code class="xref std std-envvar docutils literal notranslate"><span class="pre">SSLKEYLOGFILE</span></code> was added.</p>435</div>436<div class="versionchanged">437<p><span class="versionmodified changed">Changed in version 3.10: </span>The context now uses <a class="reference internal" href="#ssl.PROTOCOL_TLS_CLIENT" title="ssl.PROTOCOL_TLS_CLIENT"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS_CLIENT</span></code></a> or438<a class="reference internal" href="#ssl.PROTOCOL_TLS_SERVER" title="ssl.PROTOCOL_TLS_SERVER"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS_SERVER</span></code></a> protocol instead of generic439<a class="reference internal" href="#ssl.PROTOCOL_TLS" title="ssl.PROTOCOL_TLS"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS</span></code></a>.</p>440</div>441<div class="versionchanged">442<p><span class="versionmodified changed">Changed in version 3.13: </span>The context now uses <a class="reference internal" href="#ssl.VERIFY_X509_PARTIAL_CHAIN" title="ssl.VERIFY_X509_PARTIAL_CHAIN"><code class="xref py py-data docutils literal notranslate"><span class="pre">VERIFY_X509_PARTIAL_CHAIN</span></code></a> and443<a class="reference internal" href="#ssl.VERIFY_X509_STRICT" title="ssl.VERIFY_X509_STRICT"><code class="xref py py-data docutils literal notranslate"><span class="pre">VERIFY_X509_STRICT</span></code></a> in its default verify flags.</p>444</div>445</dd></dl>446 447</section>448<section id="signature-algorithms">449<h3>Signature algorithms<a class="headerlink" href="#signature-algorithms" title="Link to this heading">¶</a></h3>450<dl class="py function">451<dt class="sig sig-object py" id="ssl.get_sigalgs">452<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">get_sigalgs</span></span><span class="sig-paren">(</span><span class="sig-paren">)</span><a class="headerlink" href="#ssl.get_sigalgs" title="Link to this definition">¶</a></dt>453<dd><p>Return a list of available TLS signature algorithm names used454by servers to complete the TLS handshake or clients requesting455certificate-based authentication. For example:</p>456<div class="highlight-python3 notranslate"><div class="highlight"><pre><span></span><span class="gp">&gt;&gt;&gt; </span><span class="n">ssl</span><span class="o">.</span><span class="n">get_sigalgs</span><span class="p">()</span>457<span class="go">[&#39;ecdsa_secp256r1_sha256&#39;, &#39;ecdsa_secp384r1_sha384&#39;, ...]</span>458</pre></div>459</div>460<p>These names can be used when building string values to pass to the461<a class="reference internal" href="#ssl.SSLContext.set_client_sigalgs" title="ssl.SSLContext.set_client_sigalgs"><code class="xref py py-meth docutils literal notranslate"><span class="pre">SSLContext.set_client_sigalgs()</span></code></a> and462<a class="reference internal" href="#ssl.SSLContext.set_server_sigalgs" title="ssl.SSLContext.set_server_sigalgs"><code class="xref py py-meth docutils literal notranslate"><span class="pre">SSLContext.set_server_sigalgs()</span></code></a> methods.</p>463<div class="versionadded">464<p><span class="versionmodified added">Added in version 3.15.</span></p>465</div>466</dd></dl>467 468</section>469<section id="exceptions">470<h3>Exceptions<a class="headerlink" href="#exceptions" title="Link to this heading">¶</a></h3>471<dl class="py exception">472<dt class="sig sig-object py" id="ssl.SSLError">473<em class="property"><span class="k"><span class="pre">exception</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">SSLError</span></span><a class="headerlink" href="#ssl.SSLError" title="Link to this definition">¶</a></dt>474<dd><p>Raised to signal an error from the underlying SSL implementation475(currently provided by the OpenSSL library).  This signifies some476problem in the higher-level encryption and authentication layer that’s477superimposed on the underlying network connection.  This error478is a subtype of <a class="reference internal" href="exceptions.html#OSError" title="OSError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">OSError</span></code></a>.  The error code and message of479<code class="xref py py-exc docutils literal notranslate"><span class="pre">SSLError</span></code> instances are provided by the OpenSSL library.</p>480<div class="versionchanged">481<p><span class="versionmodified changed">Changed in version 3.3: </span><code class="xref py py-exc docutils literal notranslate"><span class="pre">SSLError</span></code> used to be a subtype of <a class="reference internal" href="socket.html#socket.error" title="socket.error"><code class="xref py py-exc docutils literal notranslate"><span class="pre">socket.error</span></code></a>.</p>482</div>483<dl class="py attribute">484<dt class="sig sig-object py" id="ssl.SSLError.library">485<span class="sig-name descname"><span class="pre">library</span></span><a class="headerlink" href="#ssl.SSLError.library" title="Link to this definition">¶</a></dt>486<dd><p>A string mnemonic designating the OpenSSL submodule in which the error487occurred, such as <code class="docutils literal notranslate"><span class="pre">SSL</span></code>, <code class="docutils literal notranslate"><span class="pre">PEM</span></code> or <code class="docutils literal notranslate"><span class="pre">X509</span></code>.  The range of possible488values depends on the OpenSSL version.</p>489<div class="versionadded">490<p><span class="versionmodified added">Added in version 3.3.</span></p>491</div>492</dd></dl>493 494<dl class="py attribute">495<dt class="sig sig-object py" id="ssl.SSLError.reason">496<span class="sig-name descname"><span class="pre">reason</span></span><a class="headerlink" href="#ssl.SSLError.reason" title="Link to this definition">¶</a></dt>497<dd><p>A string mnemonic designating the reason this error occurred, for498example <code class="docutils literal notranslate"><span class="pre">CERTIFICATE_VERIFY_FAILED</span></code>.  The range of possible499values depends on the OpenSSL version.</p>500<div class="versionadded">501<p><span class="versionmodified added">Added in version 3.3.</span></p>502</div>503</dd></dl>504 505</dd></dl>506 507<dl class="py exception">508<dt class="sig sig-object py" id="ssl.SSLZeroReturnError">509<em class="property"><span class="k"><span class="pre">exception</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">SSLZeroReturnError</span></span><a class="headerlink" href="#ssl.SSLZeroReturnError" title="Link to this definition">¶</a></dt>510<dd><p>A subclass of <a class="reference internal" href="#ssl.SSLError" title="ssl.SSLError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">SSLError</span></code></a> raised when trying to read or write and511the SSL connection has been closed cleanly.  Note that this doesn’t512mean that the underlying transport (read TCP) has been closed.</p>513<div class="versionadded">514<p><span class="versionmodified added">Added in version 3.3.</span></p>515</div>516</dd></dl>517 518<dl class="py exception">519<dt class="sig sig-object py" id="ssl.SSLWantReadError">520<em class="property"><span class="k"><span class="pre">exception</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">SSLWantReadError</span></span><a class="headerlink" href="#ssl.SSLWantReadError" title="Link to this definition">¶</a></dt>521<dd><p>A subclass of <a class="reference internal" href="#ssl.SSLError" title="ssl.SSLError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">SSLError</span></code></a> raised by a <a class="reference internal" href="#ssl-nonblocking"><span class="std std-ref">non-blocking SSL socket</span></a> when trying to read or write data, but more data needs522to be received on the underlying TCP transport before the request can be523fulfilled.</p>524<div class="versionadded">525<p><span class="versionmodified added">Added in version 3.3.</span></p>526</div>527</dd></dl>528 529<dl class="py exception">530<dt class="sig sig-object py" id="ssl.SSLWantWriteError">531<em class="property"><span class="k"><span class="pre">exception</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">SSLWantWriteError</span></span><a class="headerlink" href="#ssl.SSLWantWriteError" title="Link to this definition">¶</a></dt>532<dd><p>A subclass of <a class="reference internal" href="#ssl.SSLError" title="ssl.SSLError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">SSLError</span></code></a> raised by a <a class="reference internal" href="#ssl-nonblocking"><span class="std std-ref">non-blocking SSL socket</span></a> when trying to read or write data, but more data needs533to be sent on the underlying TCP transport before the request can be534fulfilled.</p>535<div class="versionadded">536<p><span class="versionmodified added">Added in version 3.3.</span></p>537</div>538</dd></dl>539 540<dl class="py exception">541<dt class="sig sig-object py" id="ssl.SSLSyscallError">542<em class="property"><span class="k"><span class="pre">exception</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">SSLSyscallError</span></span><a class="headerlink" href="#ssl.SSLSyscallError" title="Link to this definition">¶</a></dt>543<dd><p>A subclass of <a class="reference internal" href="#ssl.SSLError" title="ssl.SSLError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">SSLError</span></code></a> raised when a system error was encountered544while trying to fulfill an operation on a SSL socket.  Unfortunately,545there is no easy way to inspect the original errno number.</p>546<div class="versionadded">547<p><span class="versionmodified added">Added in version 3.3.</span></p>548</div>549</dd></dl>550 551<dl class="py exception">552<dt class="sig sig-object py" id="ssl.SSLEOFError">553<em class="property"><span class="k"><span class="pre">exception</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">SSLEOFError</span></span><a class="headerlink" href="#ssl.SSLEOFError" title="Link to this definition">¶</a></dt>554<dd><p>A subclass of <a class="reference internal" href="#ssl.SSLError" title="ssl.SSLError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">SSLError</span></code></a> raised when the SSL connection has been555terminated abruptly.  Generally, you shouldn’t try to reuse the underlying556transport when this error is encountered.</p>557<div class="versionadded">558<p><span class="versionmodified added">Added in version 3.3.</span></p>559</div>560</dd></dl>561 562<dl class="py exception">563<dt class="sig sig-object py" id="ssl.SSLCertVerificationError">564<em class="property"><span class="k"><span class="pre">exception</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">SSLCertVerificationError</span></span><a class="headerlink" href="#ssl.SSLCertVerificationError" title="Link to this definition">¶</a></dt>565<dd><p>A subclass of <a class="reference internal" href="#ssl.SSLError" title="ssl.SSLError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">SSLError</span></code></a> raised when certificate validation has566failed.</p>567<div class="versionadded">568<p><span class="versionmodified added">Added in version 3.7.</span></p>569</div>570<dl class="py attribute">571<dt class="sig sig-object py" id="ssl.SSLCertVerificationError.verify_code">572<span class="sig-name descname"><span class="pre">verify_code</span></span><a class="headerlink" href="#ssl.SSLCertVerificationError.verify_code" title="Link to this definition">¶</a></dt>573<dd><p>A numeric error number that denotes the verification error.</p>574</dd></dl>575 576<dl class="py attribute">577<dt class="sig sig-object py" id="ssl.SSLCertVerificationError.verify_message">578<span class="sig-name descname"><span class="pre">verify_message</span></span><a class="headerlink" href="#ssl.SSLCertVerificationError.verify_message" title="Link to this definition">¶</a></dt>579<dd><p>A human readable string of the verification error.</p>580</dd></dl>581 582</dd></dl>583 584<dl class="py exception">585<dt class="sig sig-object py" id="ssl.CertificateError">586<em class="property"><span class="k"><span class="pre">exception</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">CertificateError</span></span><a class="headerlink" href="#ssl.CertificateError" title="Link to this definition">¶</a></dt>587<dd><p>An alias for <a class="reference internal" href="#ssl.SSLCertVerificationError" title="ssl.SSLCertVerificationError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">SSLCertVerificationError</span></code></a>.</p>588<div class="versionchanged">589<p><span class="versionmodified changed">Changed in version 3.7: </span>The exception is now an alias for <a class="reference internal" href="#ssl.SSLCertVerificationError" title="ssl.SSLCertVerificationError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">SSLCertVerificationError</span></code></a>.</p>590</div>591</dd></dl>592 593</section>594<section id="random-generation">595<h3>Random generation<a class="headerlink" href="#random-generation" title="Link to this heading">¶</a></h3>596<dl class="py function">597<dt class="sig sig-object py" id="ssl.RAND_bytes">598<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">RAND_bytes</span></span><span class="sig-paren">(</span><em class="sig-param"><span class="n"><span class="pre">num</span></span></em>, <em class="sig-param"><span class="positional-only-separator o"><abbr title="Positional-only parameter separator (PEP 570)"><span class="pre">/</span></abbr></span></em><span class="sig-paren">)</span><a class="headerlink" href="#ssl.RAND_bytes" title="Link to this definition">¶</a></dt>599<dd><p>Return <em>num</em> cryptographically strong pseudo-random bytes. Raises an600<a class="reference internal" href="#ssl.SSLError" title="ssl.SSLError"><code class="xref py py-class docutils literal notranslate"><span class="pre">SSLError</span></code></a> if the PRNG has not been seeded with enough data or if the601operation is not supported by the current RAND method. <a class="reference internal" href="#ssl.RAND_status" title="ssl.RAND_status"><code class="xref py py-func docutils literal notranslate"><span class="pre">RAND_status()</span></code></a>602can be used to check the status of the PRNG and <a class="reference internal" href="#ssl.RAND_add" title="ssl.RAND_add"><code class="xref py py-func docutils literal notranslate"><span class="pre">RAND_add()</span></code></a> can be used603to seed the PRNG.</p>604<p>For almost all applications <a class="reference internal" href="os.html#os.urandom" title="os.urandom"><code class="xref py py-func docutils literal notranslate"><span class="pre">os.urandom()</span></code></a> is preferable.</p>605<p>Read the Wikipedia article, <a class="reference external" href="https://en.wikipedia.org/wiki/Cryptographically_secure_pseudorandom_number_generator">Cryptographically secure pseudorandom number606generator (CSPRNG)</a>,607to get the requirements of a cryptographically strong generator.</p>608<div class="versionadded">609<p><span class="versionmodified added">Added in version 3.3.</span></p>610</div>611</dd></dl>612 613<dl class="py function">614<dt class="sig sig-object py" id="ssl.RAND_status">615<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">RAND_status</span></span><span class="sig-paren">(</span><span class="sig-paren">)</span><a class="headerlink" href="#ssl.RAND_status" title="Link to this definition">¶</a></dt>616<dd><p>Return <code class="docutils literal notranslate"><span class="pre">True</span></code> if the SSL pseudo-random number generator has been seeded617with ‘enough’ randomness, and <code class="docutils literal notranslate"><span class="pre">False</span></code> otherwise.  Use <a class="reference internal" href="#ssl.RAND_add" title="ssl.RAND_add"><code class="xref py py-func docutils literal notranslate"><span class="pre">ssl.RAND_add()</span></code></a>618to increase the randomness of the pseudo-random number generator.</p>619</dd></dl>620 621<dl class="py function">622<dt class="sig sig-object py" id="ssl.RAND_add">623<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">RAND_add</span></span><span class="sig-paren">(</span><em class="sig-param"><span class="n"><span class="pre">bytes</span></span></em>, <em class="sig-param"><span class="n"><span class="pre">entropy</span></span></em>, <em class="sig-param"><span class="positional-only-separator o"><abbr title="Positional-only parameter separator (PEP 570)"><span class="pre">/</span></abbr></span></em><span class="sig-paren">)</span><a class="headerlink" href="#ssl.RAND_add" title="Link to this definition">¶</a></dt>624<dd><p>Mix the given <em>bytes</em> into the SSL pseudo-random number generator.  The625parameter <em>entropy</em> (a float) is a lower bound on the entropy contained in626string (so you can always use <code class="docutils literal notranslate"><span class="pre">0.0</span></code>).  See <span class="target" id="index-7"></span><a class="rfc reference external" href="https://datatracker.ietf.org/doc/html/rfc1750.html"><strong>RFC 1750</strong></a> for more627information on sources of entropy.</p>628<div class="versionchanged">629<p><span class="versionmodified changed">Changed in version 3.5: </span>Writable <a class="reference internal" href="../glossary.html#term-bytes-like-object"><span class="xref std std-term">bytes-like object</span></a> is now accepted.</p>630</div>631</dd></dl>632 633</section>634<section id="certificate-handling">635<h3>Certificate handling<a class="headerlink" href="#certificate-handling" title="Link to this heading">¶</a></h3>636<dl class="py function">637<dt class="sig sig-object py" id="ssl.cert_time_to_seconds">638<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">cert_time_to_seconds</span></span><span class="sig-paren">(</span><em class="sig-param"><span class="n"><span class="pre">cert_time</span></span></em><span class="sig-paren">)</span><a class="headerlink" href="#ssl.cert_time_to_seconds" title="Link to this definition">¶</a></dt>639<dd><p>Return the time in seconds since the Epoch, given the <code class="docutils literal notranslate"><span class="pre">cert_time</span></code>640string representing the “notBefore” or “notAfter” date from a641certificate in <code class="docutils literal notranslate"><span class="pre">&quot;%b</span> <span class="pre">%d</span> <span class="pre">%H:%M:%S</span> <span class="pre">%Y</span> <span class="pre">%Z&quot;</span></code> strptime format (C642locale).</p>643<p>Here’s an example:</p>644<div class="highlight-pycon notranslate"><div class="highlight"><pre><span></span><span class="gp">&gt;&gt;&gt; </span><span class="kn">import</span><span class="w"> </span><span class="nn">ssl</span>645<span class="gp">&gt;&gt;&gt; </span><span class="n">timestamp</span> <span class="o">=</span> <span class="n">ssl</span><span class="o">.</span><span class="n">cert_time_to_seconds</span><span class="p">(</span><span class="s2">&quot;Jan  5 09:34:43 2018 GMT&quot;</span><span class="p">)</span>646<span class="gp">&gt;&gt;&gt; </span><span class="n">timestamp</span>647<span class="go">1515144883</span>648<span class="gp">&gt;&gt;&gt; </span><span class="kn">from</span><span class="w"> </span><span class="nn">datetime</span><span class="w"> </span><span class="kn">import</span> <span class="n">datetime</span>649<span class="gp">&gt;&gt;&gt; </span><span class="nb">print</span><span class="p">(</span><span class="n">datetime</span><span class="o">.</span><span class="n">utcfromtimestamp</span><span class="p">(</span><span class="n">timestamp</span><span class="p">))</span>650<span class="go">2018-01-05 09:34:43</span>651</pre></div>652</div>653<p>“notBefore” or “notAfter” dates must use GMT (<span class="target" id="index-8"></span><a class="rfc reference external" href="https://datatracker.ietf.org/doc/html/rfc5280.html"><strong>RFC 5280</strong></a>).</p>654<div class="versionchanged">655<p><span class="versionmodified changed">Changed in version 3.5: </span>Interpret the input time as a time in UTC as specified by ‘GMT’656timezone in the input string. Local timezone was used657previously. Return an integer (no fractions of a second in the658input format)</p>659</div>660</dd></dl>661 662<dl class="py function">663<dt class="sig sig-object py" id="ssl.get_server_certificate">664<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">get_server_certificate</span></span><span class="sig-paren">(</span><em class="sig-param"><span class="n"><span class="pre">addr</span></span></em>, <em class="sig-param"><span class="n"><span class="pre">ssl_version=PROTOCOL_TLS_CLIENT</span></span></em>, <em class="sig-param"><span class="n"><span class="pre">ca_certs=None</span></span></em><span class="optional">[</span>, <em class="sig-param"><span class="n"><span class="pre">timeout</span></span></em><span class="optional">]</span><span class="sig-paren">)</span><a class="headerlink" href="#ssl.get_server_certificate" title="Link to this definition">¶</a></dt>665<dd><p>Given the address <code class="docutils literal notranslate"><span class="pre">addr</span></code> of an SSL-protected server, as a (<em>hostname</em>,666<em>port-number</em>) pair, fetches the server’s certificate, and returns it as a667PEM-encoded string.  If <code class="docutils literal notranslate"><span class="pre">ssl_version</span></code> is specified, uses that version of668the SSL protocol to attempt to connect to the server.  If <em>ca_certs</em> is669specified, it should be a file containing a list of root certificates, the670same format as used for the <em>cafile</em> parameter in671<a class="reference internal" href="#ssl.SSLContext.load_verify_locations" title="ssl.SSLContext.load_verify_locations"><code class="xref py py-meth docutils literal notranslate"><span class="pre">SSLContext.load_verify_locations()</span></code></a>.  The call will attempt to validate the672server certificate against that set of root certificates, and will fail673if the validation attempt fails.  A timeout can be specified with the674<code class="docutils literal notranslate"><span class="pre">timeout</span></code> parameter.</p>675<div class="versionchanged">676<p><span class="versionmodified changed">Changed in version 3.3: </span>This function is now IPv6-compatible.</p>677</div>678<div class="versionchanged">679<p><span class="versionmodified changed">Changed in version 3.5: </span>The default <em>ssl_version</em> is changed from <a class="reference internal" href="#ssl.PROTOCOL_SSLv3" title="ssl.PROTOCOL_SSLv3"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_SSLv3</span></code></a> to680<a class="reference internal" href="#ssl.PROTOCOL_TLS" title="ssl.PROTOCOL_TLS"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS</span></code></a> for maximum compatibility with modern servers.</p>681</div>682<div class="versionchanged">683<p><span class="versionmodified changed">Changed in version 3.10: </span>The <em>timeout</em> parameter was added.</p>684</div>685</dd></dl>686 687<dl class="py function">688<dt class="sig sig-object py" id="ssl.DER_cert_to_PEM_cert">689<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">DER_cert_to_PEM_cert</span></span><span class="sig-paren">(</span><em class="sig-param"><span class="n"><span class="pre">der_cert_bytes</span></span></em><span class="sig-paren">)</span><a class="headerlink" href="#ssl.DER_cert_to_PEM_cert" title="Link to this definition">¶</a></dt>690<dd><p>Given a certificate as a DER-encoded blob of bytes, returns a PEM-encoded691string version of the same certificate.</p>692</dd></dl>693 694<dl class="py function">695<dt class="sig sig-object py" id="ssl.PEM_cert_to_DER_cert">696<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">PEM_cert_to_DER_cert</span></span><span class="sig-paren">(</span><em class="sig-param"><span class="n"><span class="pre">pem_cert_string</span></span></em><span class="sig-paren">)</span><a class="headerlink" href="#ssl.PEM_cert_to_DER_cert" title="Link to this definition">¶</a></dt>697<dd><p>Given a certificate as an ASCII PEM string, returns a DER-encoded sequence of698bytes for that same certificate.</p>699</dd></dl>700 701<dl class="py function">702<dt class="sig sig-object py" id="ssl.get_default_verify_paths">703<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">get_default_verify_paths</span></span><span class="sig-paren">(</span><span class="sig-paren">)</span><a class="headerlink" href="#ssl.get_default_verify_paths" title="Link to this definition">¶</a></dt>704<dd><p>Returns a named tuple with paths to OpenSSL’s default cafile and capath.705The paths are the same as used by706<a class="reference internal" href="#ssl.SSLContext.set_default_verify_paths" title="ssl.SSLContext.set_default_verify_paths"><code class="xref py py-meth docutils literal notranslate"><span class="pre">SSLContext.set_default_verify_paths()</span></code></a>. The return value is a707<a class="reference internal" href="../glossary.html#term-named-tuple"><span class="xref std std-term">named tuple</span></a> <code class="docutils literal notranslate"><span class="pre">DefaultVerifyPaths</span></code>:</p>708<ul class="simple">709<li><p><code class="xref py py-attr docutils literal notranslate"><span class="pre">cafile</span></code> - resolved path to cafile or <code class="docutils literal notranslate"><span class="pre">None</span></code> if the file doesn’t exist,</p></li>710<li><p><code class="xref py py-attr docutils literal notranslate"><span class="pre">capath</span></code> - resolved path to capath or <code class="docutils literal notranslate"><span class="pre">None</span></code> if the directory doesn’t exist,</p></li>711<li><p><code class="xref py py-attr docutils literal notranslate"><span class="pre">openssl_cafile_env</span></code> - OpenSSL’s environment key that points to a cafile,</p></li>712<li><p><code class="xref py py-attr docutils literal notranslate"><span class="pre">openssl_cafile</span></code> - hard coded path to a cafile,</p></li>713<li><p><code class="xref py py-attr docutils literal notranslate"><span class="pre">openssl_capath_env</span></code> - OpenSSL’s environment key that points to a capath,</p></li>714<li><p><code class="xref py py-attr docutils literal notranslate"><span class="pre">openssl_capath</span></code> - hard coded path to a capath directory</p></li>715</ul>716<div class="versionadded">717<p><span class="versionmodified added">Added in version 3.4.</span></p>718</div>719</dd></dl>720 721<dl class="py function">722<dt class="sig sig-object py" id="ssl.enum_certificates">723<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">enum_certificates</span></span><span class="sig-paren">(</span><em class="sig-param"><span class="n"><span class="pre">store_name</span></span></em><span class="sig-paren">)</span><a class="headerlink" href="#ssl.enum_certificates" title="Link to this definition">¶</a></dt>724<dd><p>Retrieve certificates from Windows’ system cert store. <em>store_name</em> may be725one of <code class="docutils literal notranslate"><span class="pre">CA</span></code>, <code class="docutils literal notranslate"><span class="pre">ROOT</span></code> or <code class="docutils literal notranslate"><span class="pre">MY</span></code>. Windows may provide additional cert726stores, too.</p>727<p>The function returns a list of (cert_bytes, encoding_type, trust) tuples.728The encoding_type specifies the encoding of cert_bytes. It is either729<code class="xref py py-const docutils literal notranslate"><span class="pre">x509_asn</span></code> for X.509 ASN.1 data or <code class="xref py py-const docutils literal notranslate"><span class="pre">pkcs_7_asn</span></code> for730PKCS#7 ASN.1 data. Trust specifies the purpose of the certificate as a set731of OIDS or exactly <code class="docutils literal notranslate"><span class="pre">True</span></code> if the certificate is trustworthy for all732purposes.</p>733<p>Example:</p>734<div class="highlight-python3 notranslate"><div class="highlight"><pre><span></span><span class="gp">&gt;&gt;&gt; </span><span class="n">ssl</span><span class="o">.</span><span class="n">enum_certificates</span><span class="p">(</span><span class="s2">&quot;CA&quot;</span><span class="p">)</span>735<span class="go">[(b&#39;data...&#39;, &#39;x509_asn&#39;, {&#39;1.3.6.1.5.5.7.3.1&#39;, &#39;1.3.6.1.5.5.7.3.2&#39;}),</span>736<span class="go"> (b&#39;data...&#39;, &#39;x509_asn&#39;, True)]</span>737</pre></div>738</div>739<div class="availability docutils container">740<p><a class="reference internal" href="intro.html#availability"><span class="std std-ref">Availability</span></a>: Windows.</p>741</div>742<div class="versionadded">743<p><span class="versionmodified added">Added in version 3.4.</span></p>744</div>745</dd></dl>746 747<dl class="py function">748<dt class="sig sig-object py" id="ssl.enum_crls">749<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">enum_crls</span></span><span class="sig-paren">(</span><em class="sig-param"><span class="n"><span class="pre">store_name</span></span></em><span class="sig-paren">)</span><a class="headerlink" href="#ssl.enum_crls" title="Link to this definition">¶</a></dt>750<dd><p>Retrieve CRLs from Windows’ system cert store. <em>store_name</em> may be751one of <code class="docutils literal notranslate"><span class="pre">CA</span></code>, <code class="docutils literal notranslate"><span class="pre">ROOT</span></code> or <code class="docutils literal notranslate"><span class="pre">MY</span></code>. Windows may provide additional cert752stores, too.</p>753<p>The function returns a list of (cert_bytes, encoding_type, trust) tuples.754The encoding_type specifies the encoding of cert_bytes. It is either755<code class="xref py py-const docutils literal notranslate"><span class="pre">x509_asn</span></code> for X.509 ASN.1 data or <code class="xref py py-const docutils literal notranslate"><span class="pre">pkcs_7_asn</span></code> for756PKCS#7 ASN.1 data.</p>757<div class="availability docutils container">758<p><a class="reference internal" href="intro.html#availability"><span class="std std-ref">Availability</span></a>: Windows.</p>759</div>760<div class="versionadded">761<p><span class="versionmodified added">Added in version 3.4.</span></p>762</div>763</dd></dl>764 765</section>766<section id="constants">767<h3>Constants<a class="headerlink" href="#constants" title="Link to this heading">¶</a></h3>768<blockquote>769<div><p>All constants are now <a class="reference internal" href="enum.html#enum.IntEnum" title="enum.IntEnum"><code class="xref py py-class docutils literal notranslate"><span class="pre">enum.IntEnum</span></code></a> or <a class="reference internal" href="enum.html#enum.IntFlag" title="enum.IntFlag"><code class="xref py py-class docutils literal notranslate"><span class="pre">enum.IntFlag</span></code></a> collections.</p>770<div class="versionadded">771<p><span class="versionmodified added">Added in version 3.6.</span></p>772</div>773</div></blockquote>774<dl class="py data">775<dt class="sig sig-object py" id="ssl.CERT_NONE">776<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">CERT_NONE</span></span><a class="headerlink" href="#ssl.CERT_NONE" title="Link to this definition">¶</a></dt>777<dd><p>Possible value for <a class="reference internal" href="#ssl.SSLContext.verify_mode" title="ssl.SSLContext.verify_mode"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.verify_mode</span></code></a>.778Except for <a class="reference internal" href="#ssl.PROTOCOL_TLS_CLIENT" title="ssl.PROTOCOL_TLS_CLIENT"><code class="xref py py-const docutils literal notranslate"><span class="pre">PROTOCOL_TLS_CLIENT</span></code></a>,779it is the default mode.  With client-side sockets, just about any780cert is accepted.  Validation errors, such as untrusted or expired cert,781are ignored and do not abort the TLS/SSL handshake.</p>782<p>In server mode, no certificate is requested from the client, so the client783does not send any for client cert authentication.</p>784<p>See the discussion of <a class="reference internal" href="#ssl-security"><span class="std std-ref">Security considerations</span></a> below.</p>785</dd></dl>786 787<dl class="py data">788<dt class="sig sig-object py" id="ssl.CERT_OPTIONAL">789<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">CERT_OPTIONAL</span></span><a class="headerlink" href="#ssl.CERT_OPTIONAL" title="Link to this definition">¶</a></dt>790<dd><p>Possible value for <a class="reference internal" href="#ssl.SSLContext.verify_mode" title="ssl.SSLContext.verify_mode"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.verify_mode</span></code></a>.791In client mode, <a class="reference internal" href="#ssl.CERT_OPTIONAL" title="ssl.CERT_OPTIONAL"><code class="xref py py-const docutils literal notranslate"><span class="pre">CERT_OPTIONAL</span></code></a>792has the same meaning as <a class="reference internal" href="#ssl.CERT_REQUIRED" title="ssl.CERT_REQUIRED"><code class="xref py py-const docutils literal notranslate"><span class="pre">CERT_REQUIRED</span></code></a>. It is recommended to793use <code class="xref py py-const docutils literal notranslate"><span class="pre">CERT_REQUIRED</span></code> for client-side sockets instead.</p>794<p>In server mode, a client certificate request is sent to the client.  The795client may either ignore the request or send a certificate in order796perform TLS client cert authentication.  If the client chooses to send797a certificate, it is verified.  Any verification error immediately aborts798the TLS handshake.</p>799<p>Use of this setting requires a valid set of CA certificates to800be passed to <a class="reference internal" href="#ssl.SSLContext.load_verify_locations" title="ssl.SSLContext.load_verify_locations"><code class="xref py py-meth docutils literal notranslate"><span class="pre">SSLContext.load_verify_locations()</span></code></a>.</p>801</dd></dl>802 803<dl class="py data">804<dt class="sig sig-object py" id="ssl.CERT_REQUIRED">805<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">CERT_REQUIRED</span></span><a class="headerlink" href="#ssl.CERT_REQUIRED" title="Link to this definition">¶</a></dt>806<dd><p>Possible value for <a class="reference internal" href="#ssl.SSLContext.verify_mode" title="ssl.SSLContext.verify_mode"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.verify_mode</span></code></a>.807In this mode, certificates are808required from the other side of the socket connection; an <a class="reference internal" href="#ssl.SSLError" title="ssl.SSLError"><code class="xref py py-class docutils literal notranslate"><span class="pre">SSLError</span></code></a>809will be raised if no certificate is provided, or if its validation fails.810This mode is <strong>not</strong> sufficient to verify a certificate in client mode as811it does not match hostnames.  <a class="reference internal" href="#ssl.SSLContext.check_hostname" title="ssl.SSLContext.check_hostname"><code class="xref py py-attr docutils literal notranslate"><span class="pre">check_hostname</span></code></a> must be812enabled as well to verify the authenticity of a cert.813<a class="reference internal" href="#ssl.PROTOCOL_TLS_CLIENT" title="ssl.PROTOCOL_TLS_CLIENT"><code class="xref py py-const docutils literal notranslate"><span class="pre">PROTOCOL_TLS_CLIENT</span></code></a> uses <a class="reference internal" href="#ssl.CERT_REQUIRED" title="ssl.CERT_REQUIRED"><code class="xref py py-const docutils literal notranslate"><span class="pre">CERT_REQUIRED</span></code></a> and814enables <code class="xref py py-attr docutils literal notranslate"><span class="pre">check_hostname</span></code> by default.</p>815<p>With server socket, this mode provides mandatory TLS client cert816authentication.  A client certificate request is sent to the client and817the client must provide a valid and trusted certificate.</p>818<p>Use of this setting requires a valid set of CA certificates to819be passed to <a class="reference internal" href="#ssl.SSLContext.load_verify_locations" title="ssl.SSLContext.load_verify_locations"><code class="xref py py-meth docutils literal notranslate"><span class="pre">SSLContext.load_verify_locations()</span></code></a>.</p>820</dd></dl>821 822<dl class="py class">823<dt class="sig sig-object py" id="ssl.VerifyMode">824<em class="property"><span class="k"><span class="pre">class</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">VerifyMode</span></span><a class="headerlink" href="#ssl.VerifyMode" title="Link to this definition">¶</a></dt>825<dd><p><a class="reference internal" href="enum.html#enum.IntEnum" title="enum.IntEnum"><code class="xref py py-class docutils literal notranslate"><span class="pre">enum.IntEnum</span></code></a> collection of CERT_* constants.</p>826<div class="versionadded">827<p><span class="versionmodified added">Added in version 3.6.</span></p>828</div>829</dd></dl>830 831<dl class="py data">832<dt class="sig sig-object py" id="ssl.VERIFY_DEFAULT">833<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">VERIFY_DEFAULT</span></span><a class="headerlink" href="#ssl.VERIFY_DEFAULT" title="Link to this definition">¶</a></dt>834<dd><p>Possible value for <a class="reference internal" href="#ssl.SSLContext.verify_flags" title="ssl.SSLContext.verify_flags"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.verify_flags</span></code></a>. In this mode, certificate835revocation lists (CRLs) are not checked. By default OpenSSL does neither836require nor verify CRLs.</p>837<div class="versionadded">838<p><span class="versionmodified added">Added in version 3.4.</span></p>839</div>840</dd></dl>841 842<dl class="py data">843<dt class="sig sig-object py" id="ssl.VERIFY_CRL_CHECK_LEAF">844<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">VERIFY_CRL_CHECK_LEAF</span></span><a class="headerlink" href="#ssl.VERIFY_CRL_CHECK_LEAF" title="Link to this definition">¶</a></dt>845<dd><p>Possible value for <a class="reference internal" href="#ssl.SSLContext.verify_flags" title="ssl.SSLContext.verify_flags"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.verify_flags</span></code></a>. In this mode, only the846peer cert is checked but none of the intermediate CA certificates. The mode847requires a valid CRL that is signed by the peer cert’s issuer (its direct848ancestor CA). If no proper CRL has been loaded with849<a class="reference internal" href="#ssl.SSLContext.load_verify_locations" title="ssl.SSLContext.load_verify_locations"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.load_verify_locations</span></code></a>, validation will fail.</p>850<div class="versionadded">851<p><span class="versionmodified added">Added in version 3.4.</span></p>852</div>853</dd></dl>854 855<dl class="py data">856<dt class="sig sig-object py" id="ssl.VERIFY_CRL_CHECK_CHAIN">857<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">VERIFY_CRL_CHECK_CHAIN</span></span><a class="headerlink" href="#ssl.VERIFY_CRL_CHECK_CHAIN" title="Link to this definition">¶</a></dt>858<dd><p>Possible value for <a class="reference internal" href="#ssl.SSLContext.verify_flags" title="ssl.SSLContext.verify_flags"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.verify_flags</span></code></a>. In this mode, CRLs of859all certificates in the peer cert chain are checked.</p>860<div class="versionadded">861<p><span class="versionmodified added">Added in version 3.4.</span></p>862</div>863</dd></dl>864 865<dl class="py data">866<dt class="sig sig-object py" id="ssl.VERIFY_X509_STRICT">867<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">VERIFY_X509_STRICT</span></span><a class="headerlink" href="#ssl.VERIFY_X509_STRICT" title="Link to this definition">¶</a></dt>868<dd><p>Possible value for <a class="reference internal" href="#ssl.SSLContext.verify_flags" title="ssl.SSLContext.verify_flags"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.verify_flags</span></code></a> to disable workarounds869for broken X.509 certificates.</p>870<div class="versionadded">871<p><span class="versionmodified added">Added in version 3.4.</span></p>872</div>873</dd></dl>874 875<dl class="py data">876<dt class="sig sig-object py" id="ssl.VERIFY_ALLOW_PROXY_CERTS">877<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">VERIFY_ALLOW_PROXY_CERTS</span></span><a class="headerlink" href="#ssl.VERIFY_ALLOW_PROXY_CERTS" title="Link to this definition">¶</a></dt>878<dd><p>Possible value for <a class="reference internal" href="#ssl.SSLContext.verify_flags" title="ssl.SSLContext.verify_flags"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.verify_flags</span></code></a> to enables proxy879certificate verification.</p>880<div class="versionadded">881<p><span class="versionmodified added">Added in version 3.10.</span></p>882</div>883</dd></dl>884 885<dl class="py data">886<dt class="sig sig-object py" id="ssl.VERIFY_X509_TRUSTED_FIRST">887<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">VERIFY_X509_TRUSTED_FIRST</span></span><a class="headerlink" href="#ssl.VERIFY_X509_TRUSTED_FIRST" title="Link to this definition">¶</a></dt>888<dd><p>Possible value for <a class="reference internal" href="#ssl.SSLContext.verify_flags" title="ssl.SSLContext.verify_flags"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.verify_flags</span></code></a>. It instructs OpenSSL to889prefer trusted certificates when building the trust chain to validate a890certificate. This flag is enabled by default.</p>891<div class="versionadded">892<p><span class="versionmodified added">Added in version 3.4.4.</span></p>893</div>894</dd></dl>895 896<dl class="py data">897<dt class="sig sig-object py" id="ssl.VERIFY_X509_PARTIAL_CHAIN">898<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">VERIFY_X509_PARTIAL_CHAIN</span></span><a class="headerlink" href="#ssl.VERIFY_X509_PARTIAL_CHAIN" title="Link to this definition">¶</a></dt>899<dd><p>Possible value for <a class="reference internal" href="#ssl.SSLContext.verify_flags" title="ssl.SSLContext.verify_flags"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.verify_flags</span></code></a>. It instructs OpenSSL to900accept intermediate CAs in the trust store to be treated as trust-anchors,901in the same way as the self-signed root CA certificates. This makes it902possible to trust certificates issued by an intermediate CA without having903to trust its ancestor root CA.</p>904<div class="versionadded">905<p><span class="versionmodified added">Added in version 3.10.</span></p>906</div>907</dd></dl>908 909<dl class="py class">910<dt class="sig sig-object py" id="ssl.VerifyFlags">911<em class="property"><span class="k"><span class="pre">class</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">VerifyFlags</span></span><a class="headerlink" href="#ssl.VerifyFlags" title="Link to this definition">¶</a></dt>912<dd><p><a class="reference internal" href="enum.html#enum.IntFlag" title="enum.IntFlag"><code class="xref py py-class docutils literal notranslate"><span class="pre">enum.IntFlag</span></code></a> collection of VERIFY_* constants.</p>913<div class="versionadded">914<p><span class="versionmodified added">Added in version 3.6.</span></p>915</div>916</dd></dl>917 918<dl class="py data">919<dt class="sig sig-object py" id="ssl.PROTOCOL_TLS">920<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">PROTOCOL_TLS</span></span><a class="headerlink" href="#ssl.PROTOCOL_TLS" title="Link to this definition">¶</a></dt>921<dd><p>Selects the highest protocol version that both the client and server support.922Despite the name, this option can select both “SSL” and “TLS” protocols.</p>923<div class="versionadded">924<p><span class="versionmodified added">Added in version 3.6.</span></p>925</div>926<div class="deprecated">927<p><span class="versionmodified deprecated">Deprecated since version 3.10: </span>TLS clients and servers require different default settings for secure928communication. The generic TLS protocol constant is deprecated in929favor of <a class="reference internal" href="#ssl.PROTOCOL_TLS_CLIENT" title="ssl.PROTOCOL_TLS_CLIENT"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS_CLIENT</span></code></a> and <a class="reference internal" href="#ssl.PROTOCOL_TLS_SERVER" title="ssl.PROTOCOL_TLS_SERVER"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS_SERVER</span></code></a>.</p>930</div>931</dd></dl>932 933<dl class="py data">934<dt class="sig sig-object py" id="ssl.PROTOCOL_TLS_CLIENT">935<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">PROTOCOL_TLS_CLIENT</span></span><a class="headerlink" href="#ssl.PROTOCOL_TLS_CLIENT" title="Link to this definition">¶</a></dt>936<dd><p>Auto-negotiate the highest protocol version that both the client and937server support, and configure the context client-side connections. The938protocol enables <a class="reference internal" href="#ssl.CERT_REQUIRED" title="ssl.CERT_REQUIRED"><code class="xref py py-data docutils literal notranslate"><span class="pre">CERT_REQUIRED</span></code></a> and939<a class="reference internal" href="#ssl.SSLContext.check_hostname" title="ssl.SSLContext.check_hostname"><code class="xref py py-attr docutils literal notranslate"><span class="pre">check_hostname</span></code></a> by default.</p>940<div class="versionadded">941<p><span class="versionmodified added">Added in version 3.6.</span></p>942</div>943</dd></dl>944 945<dl class="py data">946<dt class="sig sig-object py" id="ssl.PROTOCOL_TLS_SERVER">947<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">PROTOCOL_TLS_SERVER</span></span><a class="headerlink" href="#ssl.PROTOCOL_TLS_SERVER" title="Link to this definition">¶</a></dt>948<dd><p>Auto-negotiate the highest protocol version that both the client and949server support, and configure the context server-side connections.</p>950<div class="versionadded">951<p><span class="versionmodified added">Added in version 3.6.</span></p>952</div>953</dd></dl>954 955<dl class="py data">956<dt class="sig sig-object py" id="ssl.PROTOCOL_SSLv23">957<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">PROTOCOL_SSLv23</span></span><a class="headerlink" href="#ssl.PROTOCOL_SSLv23" title="Link to this definition">¶</a></dt>958<dd><p>Alias for <a class="reference internal" href="#ssl.PROTOCOL_TLS" title="ssl.PROTOCOL_TLS"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS</span></code></a>.</p>959<div class="deprecated">960<p><span class="versionmodified deprecated">Deprecated since version 3.6: </span>Use <a class="reference internal" href="#ssl.PROTOCOL_TLS" title="ssl.PROTOCOL_TLS"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS</span></code></a> instead.</p>961</div>962</dd></dl>963 964<dl class="py data">965<dt class="sig sig-object py" id="ssl.PROTOCOL_SSLv3">966<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">PROTOCOL_SSLv3</span></span><a class="headerlink" href="#ssl.PROTOCOL_SSLv3" title="Link to this definition">¶</a></dt>967<dd><p>Selects SSL version 3 as the channel encryption protocol.</p>968<p>This protocol is not available if OpenSSL is compiled with the969<code class="docutils literal notranslate"><span class="pre">no-ssl3</span></code> option.</p>970<div class="admonition warning">971<p class="admonition-title">Warning</p>972<p>SSL version 3 is insecure.  Its use is highly discouraged.</p>973</div>974<div class="deprecated">975<p><span class="versionmodified deprecated">Deprecated since version 3.6: </span>OpenSSL has deprecated all version specific protocols. Use the default976protocol <a class="reference internal" href="#ssl.PROTOCOL_TLS_SERVER" title="ssl.PROTOCOL_TLS_SERVER"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS_SERVER</span></code></a> or <a class="reference internal" href="#ssl.PROTOCOL_TLS_CLIENT" title="ssl.PROTOCOL_TLS_CLIENT"><code class="xref py py-data docutils literal notranslate"><span class="pre">PROTOCOL_TLS_CLIENT</span></code></a>977with <a class="reference internal" href="#ssl.SSLContext.minimum_version" title="ssl.SSLContext.minimum_version"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.minimum_version</span></code></a> and978<a class="reference internal" href="#ssl.SSLContext.maximum_version" title="ssl.SSLContext.maximum_version"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.maximum_version</span></code></a> instead.</p>979</div>980</dd></dl>981 982<dl class="py data">983<dt class="sig sig-object py" id="ssl.PROTOCOL_TLSv1">984<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">PROTOCOL_TLSv1</span></span><a class="headerlink" href="#ssl.PROTOCOL_TLSv1" title="Link to this definition">¶</a></dt>985<dd><p>Selects TLS version 1.0 as the channel encryption protocol.</p>986<div class="deprecated">987<p><span class="versionmodified deprecated">Deprecated since version 3.6: </span>OpenSSL has deprecated all version specific protocols.</p>988</div>989</dd></dl>990 991<dl class="py data">992<dt class="sig sig-object py" id="ssl.PROTOCOL_TLSv1_1">993<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">PROTOCOL_TLSv1_1</span></span><a class="headerlink" href="#ssl.PROTOCOL_TLSv1_1" title="Link to this definition">¶</a></dt>994<dd><p>Selects TLS version 1.1 as the channel encryption protocol.995Available only with openssl version 1.0.1+.</p>996<div class="versionadded">997<p><span class="versionmodified added">Added in version 3.4.</span></p>998</div>999<div class="deprecated">1000<p><span class="versionmodified deprecated">Deprecated since version 3.6: </span>OpenSSL has deprecated all version specific protocols.</p>1001</div>1002</dd></dl>1003 1004<dl class="py data">1005<dt class="sig sig-object py" id="ssl.PROTOCOL_TLSv1_2">1006<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">PROTOCOL_TLSv1_2</span></span><a class="headerlink" href="#ssl.PROTOCOL_TLSv1_2" title="Link to this definition">¶</a></dt>1007<dd><p>Selects TLS version 1.2 as the channel encryption protocol.1008Available only with openssl version 1.0.1+.</p>1009<div class="versionadded">1010<p><span class="versionmodified added">Added in version 3.4.</span></p>1011</div>1012<div class="deprecated">1013<p><span class="versionmodified deprecated">Deprecated since version 3.6: </span>OpenSSL has deprecated all version specific protocols.</p>1014</div>1015</dd></dl>1016 1017<dl class="py data">1018<dt class="sig sig-object py" id="ssl.OP_ALL">1019<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_ALL</span></span><a class="headerlink" href="#ssl.OP_ALL" title="Link to this definition">¶</a></dt>1020<dd><p>Enables workarounds for various bugs present in other SSL implementations.1021This option is set by default.  It does not necessarily set the same1022flags as OpenSSL’s <code class="docutils literal notranslate"><span class="pre">SSL_OP_ALL</span></code> constant.</p>1023<div class="versionadded">1024<p><span class="versionmodified added">Added in version 3.2.</span></p>1025</div>1026</dd></dl>1027 1028<dl class="py data">1029<dt class="sig sig-object py" id="ssl.OP_NO_SSLv2">1030<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_NO_SSLv2</span></span><a class="headerlink" href="#ssl.OP_NO_SSLv2" title="Link to this definition">¶</a></dt>1031<dd><p>Prevents an SSLv2 connection.  This option is only applicable in1032conjunction with <a class="reference internal" href="#ssl.PROTOCOL_TLS" title="ssl.PROTOCOL_TLS"><code class="xref py py-const docutils literal notranslate"><span class="pre">PROTOCOL_TLS</span></code></a>.  It prevents the peers from1033choosing SSLv2 as the protocol version.</p>1034<div class="versionadded">1035<p><span class="versionmodified added">Added in version 3.2.</span></p>1036</div>1037<div class="deprecated">1038<p><span class="versionmodified deprecated">Deprecated since version 3.6: </span>SSLv2 is deprecated</p>1039</div>1040</dd></dl>1041 1042<dl class="py data">1043<dt class="sig sig-object py" id="ssl.OP_NO_SSLv3">1044<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_NO_SSLv3</span></span><a class="headerlink" href="#ssl.OP_NO_SSLv3" title="Link to this definition">¶</a></dt>1045<dd><p>Prevents an SSLv3 connection.  This option is only applicable in1046conjunction with <a class="reference internal" href="#ssl.PROTOCOL_TLS" title="ssl.PROTOCOL_TLS"><code class="xref py py-const docutils literal notranslate"><span class="pre">PROTOCOL_TLS</span></code></a>.  It prevents the peers from1047choosing SSLv3 as the protocol version.</p>1048<div class="versionadded">1049<p><span class="versionmodified added">Added in version 3.2.</span></p>1050</div>1051<div class="deprecated">1052<p><span class="versionmodified deprecated">Deprecated since version 3.6: </span>SSLv3 is deprecated</p>1053</div>1054</dd></dl>1055 1056<dl class="py data">1057<dt class="sig sig-object py" id="ssl.OP_NO_TLSv1">1058<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_NO_TLSv1</span></span><a class="headerlink" href="#ssl.OP_NO_TLSv1" title="Link to this definition">¶</a></dt>1059<dd><p>Prevents a TLSv1 connection.  This option is only applicable in1060conjunction with <a class="reference internal" href="#ssl.PROTOCOL_TLS" title="ssl.PROTOCOL_TLS"><code class="xref py py-const docutils literal notranslate"><span class="pre">PROTOCOL_TLS</span></code></a>.  It prevents the peers from1061choosing TLSv1 as the protocol version.</p>1062<div class="versionadded">1063<p><span class="versionmodified added">Added in version 3.2.</span></p>1064</div>1065<div class="deprecated">1066<p><span class="versionmodified deprecated">Deprecated since version 3.7: </span>The option is deprecated since OpenSSL 1.1.0, use the new1067<a class="reference internal" href="#ssl.SSLContext.minimum_version" title="ssl.SSLContext.minimum_version"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.minimum_version</span></code></a> and1068<a class="reference internal" href="#ssl.SSLContext.maximum_version" title="ssl.SSLContext.maximum_version"><code class="xref py py-attr docutils literal notranslate"><span class="pre">SSLContext.maximum_version</span></code></a> instead.</p>1069</div>1070</dd></dl>1071 1072<dl class="py data">1073<dt class="sig sig-object py" id="ssl.OP_NO_TLSv1_1">1074<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_NO_TLSv1_1</span></span><a class="headerlink" href="#ssl.OP_NO_TLSv1_1" title="Link to this definition">¶</a></dt>1075<dd><p>Prevents a TLSv1.1 connection. This option is only applicable in conjunction1076with <a class="reference internal" href="#ssl.PROTOCOL_TLS" title="ssl.PROTOCOL_TLS"><code class="xref py py-const docutils literal notranslate"><span class="pre">PROTOCOL_TLS</span></code></a>. It prevents the peers from choosing TLSv1.1 as1077the protocol version. Available only with openssl version 1.0.1+.</p>1078<div class="versionadded">1079<p><span class="versionmodified added">Added in version 3.4.</span></p>1080</div>1081<div class="deprecated">1082<p><span class="versionmodified deprecated">Deprecated since version 3.7: </span>The option is deprecated since OpenSSL 1.1.0.</p>1083</div>1084</dd></dl>1085 1086<dl class="py data">1087<dt class="sig sig-object py" id="ssl.OP_NO_TLSv1_2">1088<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_NO_TLSv1_2</span></span><a class="headerlink" href="#ssl.OP_NO_TLSv1_2" title="Link to this definition">¶</a></dt>1089<dd><p>Prevents a TLSv1.2 connection. This option is only applicable in conjunction1090with <a class="reference internal" href="#ssl.PROTOCOL_TLS" title="ssl.PROTOCOL_TLS"><code class="xref py py-const docutils literal notranslate"><span class="pre">PROTOCOL_TLS</span></code></a>. It prevents the peers from choosing TLSv1.2 as1091the protocol version. Available only with openssl version 1.0.1+.</p>1092<div class="versionadded">1093<p><span class="versionmodified added">Added in version 3.4.</span></p>1094</div>1095<div class="deprecated">1096<p><span class="versionmodified deprecated">Deprecated since version 3.7: </span>The option is deprecated since OpenSSL 1.1.0.</p>1097</div>1098</dd></dl>1099 1100<dl class="py data">1101<dt class="sig sig-object py" id="ssl.OP_NO_TLSv1_3">1102<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_NO_TLSv1_3</span></span><a class="headerlink" href="#ssl.OP_NO_TLSv1_3" title="Link to this definition">¶</a></dt>1103<dd><p>Prevents a TLSv1.3 connection. This option is only applicable in conjunction1104with <a class="reference internal" href="#ssl.PROTOCOL_TLS" title="ssl.PROTOCOL_TLS"><code class="xref py py-const docutils literal notranslate"><span class="pre">PROTOCOL_TLS</span></code></a>. It prevents the peers from choosing TLSv1.3 as1105the protocol version. TLS 1.3 is available with OpenSSL 1.1.1 or later.1106When Python has been compiled against an older version of OpenSSL, the1107flag defaults to <em>0</em>.</p>1108<div class="versionadded">1109<p><span class="versionmodified added">Added in version 3.6.3.</span></p>1110</div>1111<div class="deprecated">1112<p><span class="versionmodified deprecated">Deprecated since version 3.7: </span>The option is deprecated since OpenSSL 1.1.0. It was added to 2.7.15 and11133.6.3 for backwards compatibility with OpenSSL 1.0.2.</p>1114</div>1115</dd></dl>1116 1117<dl class="py data">1118<dt class="sig sig-object py" id="ssl.OP_NO_RENEGOTIATION">1119<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_NO_RENEGOTIATION</span></span><a class="headerlink" href="#ssl.OP_NO_RENEGOTIATION" title="Link to this definition">¶</a></dt>1120<dd><p>Disable all renegotiation in TLSv1.2 and earlier. Do not send1121HelloRequest messages, and ignore renegotiation requests via ClientHello.</p>1122<p>This option is only available with OpenSSL 1.1.0h and later.</p>1123<div class="versionadded">1124<p><span class="versionmodified added">Added in version 3.7.</span></p>1125</div>1126</dd></dl>1127 1128<dl class="py data">1129<dt class="sig sig-object py" id="ssl.OP_CIPHER_SERVER_PREFERENCE">1130<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_CIPHER_SERVER_PREFERENCE</span></span><a class="headerlink" href="#ssl.OP_CIPHER_SERVER_PREFERENCE" title="Link to this definition">¶</a></dt>1131<dd><p>Use the server’s cipher ordering preference, rather than the client’s.1132This option has no effect on client sockets and SSLv2 server sockets.</p>1133<div class="versionadded">1134<p><span class="versionmodified added">Added in version 3.3.</span></p>1135</div>1136</dd></dl>1137 1138<dl class="py data">1139<dt class="sig sig-object py" id="ssl.OP_SINGLE_DH_USE">1140<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_SINGLE_DH_USE</span></span><a class="headerlink" href="#ssl.OP_SINGLE_DH_USE" title="Link to this definition">¶</a></dt>1141<dd><p>Prevents reuse of the same DH key for distinct SSL sessions.  This1142improves forward secrecy but requires more computational resources.1143This option only applies to server sockets.</p>1144<div class="versionadded">1145<p><span class="versionmodified added">Added in version 3.3.</span></p>1146</div>1147</dd></dl>1148 1149<dl class="py data">1150<dt class="sig sig-object py" id="ssl.OP_SINGLE_ECDH_USE">1151<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_SINGLE_ECDH_USE</span></span><a class="headerlink" href="#ssl.OP_SINGLE_ECDH_USE" title="Link to this definition">¶</a></dt>1152<dd><p>Prevents reuse of the same ECDH key for distinct SSL sessions.  This1153improves forward secrecy but requires more computational resources.1154This option only applies to server sockets.</p>1155<div class="versionadded">1156<p><span class="versionmodified added">Added in version 3.3.</span></p>1157</div>1158</dd></dl>1159 1160<dl class="py data">1161<dt class="sig sig-object py" id="ssl.OP_ENABLE_MIDDLEBOX_COMPAT">1162<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_ENABLE_MIDDLEBOX_COMPAT</span></span><a class="headerlink" href="#ssl.OP_ENABLE_MIDDLEBOX_COMPAT" title="Link to this definition">¶</a></dt>1163<dd><p>Send dummy Change Cipher Spec (CCS) messages in TLS 1.3 handshake to make1164a TLS 1.3 connection look more like a TLS 1.2 connection.</p>1165<p>This option is only available with OpenSSL 1.1.1 and later.</p>1166<div class="versionadded">1167<p><span class="versionmodified added">Added in version 3.8.</span></p>1168</div>1169</dd></dl>1170 1171<dl class="py data">1172<dt class="sig sig-object py" id="ssl.OP_NO_COMPRESSION">1173<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_NO_COMPRESSION</span></span><a class="headerlink" href="#ssl.OP_NO_COMPRESSION" title="Link to this definition">¶</a></dt>1174<dd><p>Disable compression on the SSL channel.  This is useful if the application1175protocol supports its own compression scheme.</p>1176<div class="versionadded">1177<p><span class="versionmodified added">Added in version 3.3.</span></p>1178</div>1179</dd></dl>1180 1181<dl class="py class">1182<dt class="sig sig-object py" id="ssl.Options">1183<em class="property"><span class="k"><span class="pre">class</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">Options</span></span><a class="headerlink" href="#ssl.Options" title="Link to this definition">¶</a></dt>1184<dd><p><a class="reference internal" href="enum.html#enum.IntFlag" title="enum.IntFlag"><code class="xref py py-class docutils literal notranslate"><span class="pre">enum.IntFlag</span></code></a> collection of OP_* constants.</p>1185</dd></dl>1186 1187<dl class="py data">1188<dt class="sig sig-object py" id="ssl.OP_NO_TICKET">1189<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_NO_TICKET</span></span><a class="headerlink" href="#ssl.OP_NO_TICKET" title="Link to this definition">¶</a></dt>1190<dd><p>Prevent client side from requesting a session ticket.</p>1191<div class="versionadded">1192<p><span class="versionmodified added">Added in version 3.6.</span></p>1193</div>1194</dd></dl>1195 1196<dl class="py data">1197<dt class="sig sig-object py" id="ssl.OP_IGNORE_UNEXPECTED_EOF">1198<span class="sig-prename descclassname"><span class="pre">ssl.</span></span><span class="sig-name descname"><span class="pre">OP_IGNORE_UNEXPECTED_EOF</span></span><a class="headerlink" href="#ssl.OP_IGNORE_UNEXPECTED_EOF" title="Link to this definition">¶</a></dt>1199<dd><p>Ignore unexpected shutdown of TLS connections.</p>1200<p>This option is only available with OpenSSL 3.0.0 and later.</p>

Showing the first 1,200 of 3771 lines. Download the file for the rest.