Repository navigation
No way to use TLS-PSK from python ssl #63284
Description
Activity
OpenSSL supports TLS-PSK which some people (myself obviously) find to be substantially easier to use than setting up certs.
However, there's no way to use PSK via the current SSL api in python. It would be very nice to be able to use PSK from python.
For OpenSSL, even the C API is particularly easy. Attached is the implementation used in Mosquitto, a MQTT message broker that supports both cert based and PSK based TLS.
Reacted by Paolo Patruno- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or errorstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory
on Sep 24, 2013 Python 2.7 is open only for bugfixes. No new features.
Do you dare to write a patch for Python 3.4? :-). If you do, remember to sign a Contributor Agreement.
Give it a try! :)
Is it different from TLS SRP, which already has a feature request in bpo-11943?
As Jesus said, feel free to propose a patch, even a proof of concept so that we start discussing the API.- addedtype-featureA feature request or enhancementA feature request or enhancementand removedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Sep 24, 2013 This is not TLS-SRP, but TLS-PSK as described by RFC 4279[1]
There is a very small amount of overlap - the "unknown_psk_identity" error defined by PSK is also used in SRP.
This feature request has been idle for almost four years. Although TLS-PSK is nice to have, it is not a priority for protocols such as HTTPS. I neither have time nor motivation to create a patch myself. Therefore I'm closing this issue of lack of activity. Please feel free to re-open it with a patch against 3.7.
Reacted by Davy Durham6 remaining items
- added3.13only security fixesonly security fixesand removed3.7 (EOL)end of lifeend of life
on May 14, 2023 I can handle the PR review. I'm not really convinced that this feature is worth having - the original bug filer's excuse was a poor one about not wanting to deal with certificates. letsencrypt has become commonplace not to make that easy.
But so long as
sslexists and is basically a wrapper around things OpenSSL provides, there is no harm in offering the APIs. I'd expect anyone doing a security review of a system design to raise their eyebrows at PSK TLS use...Reacted by Grant Ramsay@gpshead thanks for the review!
I will update the PR soon when I get a chance.Yes, I agree with both sides of that argument.
A more common/standard use of TLS-PSK is resuming TLS sessions that were originally created by asymmetric encryption. Although possibly the TLSv1.3 PSK APIs (that I did not implement) are better suited to that.
Other use cases:
- Small embedded systems without enough resources for asymmetric encryption
- Ephemeral PSKs from a secure source - this is my use case, where a hypervisor is passing PSKs to VMs
- Some other projects seem to find a use for it:
https://docs.bareos.org/include/autogenerated/autosummary/python-bareos/bareos.bsock.html#transport-encryption-tls-psk
Reacted by Mooni123 and Roman Krmichallowasrzechonek-silvair commented
on Oct 20, 2023 More actionsI can handle the PR review. I'm not really convinced that this feature is worth having - the original bug filer's excuse was a poor one about not wanting to deal with certificates. letsencrypt has become commonplace not to make that easy.
There are situations where certificates cannot be used - in IoT it's common that the embedded device has neither RTC (to check validity) nor HTTP (to check revocation lists), and in most cases limited computing power.
Reacted by Davy Durham, Gregory P. Smith and Roman KrAn other use case will be the backup software bareos/bacula, which makes heavy usage of TLS-PSK.
Reacted by Gregory P. SmithI also need this feature for
pymobiledevice3. On very recent updates, Apple started using TLS-PSK to communicate with the device. I believe more and more people will start having problems as a result.Reacted by Grant Ramsay and Gregory P. Smith- added a commit that references this issue
on Nov 27, 2023 Thanks for the contribution!
Reacted by Grant Ramsay- added a commit that references this issue
on Nov 27, 2023 - added a commit that references this issue
on Feb 11, 2024
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields:
Linked PRs