Skip to content

No way to use TLS-PSK from python ssl #63284

Description

@karlp
mannequin
BPO 19084
Nosy @warsaw, @jcea, @pitrou, @giampaolo, @tiran, @chrysn
Files
  • 5bcfpEKD.txt: implementation of TLS-PSK from Mosquitto
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = 'https://github.com/tiran'
    closed_at = <Date 2017-09-06.14:53:17.746>
    created_at = <Date 2013-09-24.15:32:28.932>
    labels = ['3.7', 'expert-SSL', 'type-feature', 'library']
    title = 'No way to use TLS-PSK from python ssl'
    updated_at = <Date 2017-09-06.14:53:17.746>
    user = 'https://bugs.python.org/karlp'

    bugs.python.org fields:

    activity = <Date 2017-09-06.14:53:17.746>
    actor = 'christian.heimes'
    assignee = 'christian.heimes'
    closed = True
    closed_date = <Date 2017-09-06.14:53:17.746>
    closer = 'christian.heimes'
    components = ['Library (Lib)', 'SSL']
    creation = <Date 2013-09-24.15:32:28.932>
    creator = 'karlp'
    dependencies = []
    files = ['31859']
    hgrepos = []
    issue_num = 19084
    keywords = []
    message_count = 5.0
    messages = ['198362', '198364', '198365', '198378', '301475']
    nosy_count = 11.0
    nosy_names = ['barry', 'jcea', 'janssen', 'pitrou', 'giampaolo.rodola', 'christian.heimes', 'chrysn', 'karlp', 'ralight', 'njouanin', 'luizdepra']
    pr_nums = []
    priority = 'normal'
    resolution = 'out of date'
    stage = 'resolved'
    status = 'closed'
    superseder = None
    type = 'enhancement'
    url = 'https://bugs.python.org/issue19084'
    versions = ['Python 3.7']

    Linked PRs

    Activity

    1. karlp commented on Sep 24, 2013

      karlpmannequin
      MannequinAuthor

      OpenSSL supports TLS-PSK which some people (myself obviously) find to be substantially easier to use than setting up certs.

      However, there's no way to use PSK via the current SSL api in python. It would be very nice to be able to use PSK from python.

      For OpenSSL, even the C API is particularly easy. Attached is the implementation used in Mosquitto, a MQTT message broker that supports both cert based and PSK based TLS.

    2. added
      type-bugAn unexpected behavior, bug, or error
      stdlibStandard Library Python modules in the Lib/ directory
      on Sep 24, 2013
    3. jcea commented on Sep 24, 2013

      @jcea
      Member

      Python 2.7 is open only for bugfixes. No new features.

      Do you dare to write a patch for Python 3.4? :-). If you do, remember to sign a Contributor Agreement.

      Give it a try! :)

    4. pitrou commented on Sep 24, 2013

      @pitrou
      Member

      Is it different from TLS SRP, which already has a feature request in bpo-11943?
      As Jesus said, feel free to propose a patch, even a proof of concept so that we start discussing the API.

    5. added
      type-featureA feature request or enhancement
      and removed
      type-bugAn unexpected behavior, bug, or error
      on Sep 24, 2013
    6. ralight commented on Sep 25, 2013

      ralightmannequin
      Mannequin

      This is not TLS-SRP, but TLS-PSK as described by RFC 4279[1]

      There is a very small amount of overlap - the "unknown_psk_identity" error defined by PSK is also used in SRP.

      [1] http://tools.ietf.org/html/rfc4279

    7. self-assigned this
      on Sep 15, 2016
    8. tiran commented on Sep 6, 2017

      @tiran
      Member

      This feature request has been idle for almost four years. Although TLS-PSK is nice to have, it is not a priority for protocols such as HTTPS. I neither have time nor motivation to create a patch myself. Therefore I'm closing this issue of lack of activity. Please feel free to re-open it with a patch against 3.7.

    9. transferred this issue fromon Apr 10, 2022
    10. added a commit that references this issue on Apr 2, 2023
    11. 6 remaining items

    12. added
      3.13only security fixes
      and removed on May 14, 2023
    13. self-assigned this
      on May 30, 2023
    14. gpshead commented on May 30, 2023

      @gpshead
      Member

      I can handle the PR review. I'm not really convinced that this feature is worth having - the original bug filer's excuse was a poor one about not wanting to deal with certificates. letsencrypt has become commonplace not to make that easy.

      But so long as ssl exists and is basically a wrapper around things OpenSSL provides, there is no harm in offering the APIs. I'd expect anyone doing a security review of a system design to raise their eyebrows at PSK TLS use...

    15. gramsay0 commented on May 31, 2023

      @gramsay0

      @gpshead thanks for the review!
      I will update the PR soon when I get a chance.

      Yes, I agree with both sides of that argument.

      A more common/standard use of TLS-PSK is resuming TLS sessions that were originally created by asymmetric encryption. Although possibly the TLSv1.3 PSK APIs (that I did not implement) are better suited to that.

      Other use cases:

    16. michallowasrzechonek-silvair commented on Oct 20, 2023

      @michallowasrzechonek-silvair

      I can handle the PR review. I'm not really convinced that this feature is worth having - the original bug filer's excuse was a poor one about not wanting to deal with certificates. letsencrypt has become commonplace not to make that easy.

      There are situations where certificates cannot be used - in IoT it's common that the embedded device has neither RTC (to check validity) nor HTTP (to check revocation lists), and in most cases limited computing power.

    17. tuxmaster5000 commented on Nov 1, 2023

      @tuxmaster5000

      An other use case will be the backup software bareos/bacula, which makes heavy usage of TLS-PSK.

    18. doronz88 commented on Nov 26, 2023

      @doronz88

      I also need this feature for pymobiledevice3. On very recent updates, Apple started using TLS-PSK to communicate with the device. I believe more and more people will start having problems as a result.

    19. added a commit that references this issue on Nov 27, 2023
    20. gpshead commented on Nov 27, 2023

      @gpshead
      Member

      Thanks for the contribution!

    21. added a commit that references this issue on Nov 27, 2023
    22. added a commit that references this issue on Feb 11, 2024
    23. added a commit that references this issue on Sep 2, 2024
    Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

    Metadata

    Metadata

    Assignees

    Labels

    3.13only security fixesstdlibStandard Library Python modules in the Lib/ directorytopic-SSLtype-featureA feature request or enhancement

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions