Repository navigation
Add SSLContext.set_verify_callback() #75425
Description
Activity
At the moment, SSLContext.verify_mode() allows for three modes when dealing with Purpose.CLIENT_AUTH / server_side=True:
- CERT_NONE (server does not request client certificate, client does not provide it)
- CERT_OPTIONAL (server requests client certificate, raises SSLError if provided but fails verification, continues if not provided)
- CERT_REQUIRED (server requests client certificate, raises SSLError if provided but fails verification, raises SSLError if not provided)
There is currently no way to request a client certificate and manually verify it (or ignore it) if it doesn't pass OpenSSL verification. OpenSSL provides SSL_CTX_set_cert_verify_callback for using a custom callback[0], but this is not exposed in Python.
It would be nice to have a set_verify_callback() method, similar to how set_servername_callback() does it for SSL_CTX_set_tlsext_servername_callback.
[0] https://www.openssl.org/docs/man1.0.2/ssl/SSL_CTX_set_verify.html
- addedtype-featureA feature request or enhancementA feature request or enhancement
on Aug 20, 2017 Very much needing this!
My situation is a mutli-tenant asynchio-based server whereby each tenant is able to configure other clients that can connect. The current strategy requires all certs to be known up-front that, for now, necessitates a painful restart whenever new auth for a client-certificate is configured.
I also need this feature for something I'm working on, so I looked into it a bit and pushed a small proof of concept implementation to GitHub (See PR 31391).
I'm not sure if I'll have enough time to finish and clean up this implementation, but at least there is a starting point.
I also opened bpo-46779 as a simpler method to solve most of the usecases that would be solved by this api.
- added3.11only security fixesonly security fixesand removed3.8 (EOL)end of lifeend of life
on Feb 17, 2022 Unfortunately a generic and future-proof verify callback is much more work. We need to expose and wrap X509_STORE_CTX, X509_STORE, X509 (include STACK_OF(X509)), and probably several other OpenSSL structures. We also need to expose error codes.
bpo-28747 was an older ticket for implementing a callback.
I need a feature like this as well. Ideally, one could specify whether the callback replaces the verification done by OpenSSL or is in addition to it.
For myself, I need to add a handful of certificate verification checks during the TLS handshake such as checking some of the policy values. I know of no other way this could be done.
I'd also note that PyOpenSSL has this functionality (https://github.com/pyca/pyopenssl/blob/9b8c497e91ae5c50cfaf27a591698d547eee9c1d/src/OpenSSL/SSL.py#L1325 and https://github.com/pyca/pyopenssl/blob/9b8c497e91ae5c50cfaf27a591698d547eee9c1d/src/OpenSSL/SSL.py#L2035) and it is one of the reasons cited for continued use of PyOpenSSL instead of the native ssl module. Unfortunately, there are many scenarios, such as asyncio, where using PyOpenSSL is not an option.
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields: