Skip to main content

aio_gnutls_transport - asyncio transport over GnuTLS

aio_gnutls_transport provides a python3 asyncio transport over GnuTLS. It aims to be a drop-in replacement for the native SSL transport in the stdlib (and which is based on OpenSSL).

It also supports half-closed TLS connections, in other words you can .write_eof() on TLS streams (which is not possible with the native implementation).

Licence

GNU Lesser General Public License version 2.1 or any later version (LGPLv2.1+)

Requirements

  • python >= 3.6
  • gnutls >= 3.5
  • cffi >= 1.0.0

Supported platforms

  • Linux

Bugs

Bugs shall be reported in the gitlab project. Please mark security-critical issues as confidential.

Getting started

In most cases, using aio_gnutls_transport is as simple as:

from aio_gnutls_transport import ssl, GnutlsEventLoopPolicy

asyncio.set_event_loop_policy(GnutlsEventLoopPolicy())

aio_gnutls_transport.ssl is the compatibility module to be used in place of the native ssl module. It provides its own SSLContext implementation for GnuTLS.

GnutlsEventLoopPolicy is an asyncio event loop policy that installs a wrapper around the default event loop implementation to support the SSLContext objects created by the aio_gnutls_transport.ssl module.

Configuring TLS parameters

The security properties of GnutlsContext are configured using GnuTLS priority strings.

aio_gnutls_transport.DEFAULT_PRIORITY holds the default priority string set by ssl.create_default_context() (its current value is SECURE:-RSA:%PROFILE_MEDIUM:%SERVER_PRECEDENCE and it will be kept to a sane default).

The priority string is configurable on a per-context basis by calling GnuTLSContext.gnutls_set_priority(). For example, to disable TLS versions older than 1.3:

ctx = ssl.create_default_context()
ctx.gnutls_set_priority(aio_gnutls_transport.DEFAULT_PRIORITY + ":-VERS-ALL:+VERS-TLS1.3")

For any details about assembling a priority string, please refer to the GnuTLS Manual.

Contents of this package

This packages provides:

item description native equivalent
aio_gnutls_transport.GnutlsContext GnuTLS context ssl.SSLContext
aio_gnutls_transport.GnutlsError GnuTLS error class ssl.SSLError
aio_gnutls_transport.GnutlsEventLoopPolicy an asyncio event loop policy using GnutlsEventLoop instead of the default event loop asyncio.DefaultEventLoopPolicy
aio_gnutls_transport.GnutlsEventLoop an event loop which supports GnuTLS contexts asyncio.SelectorEventLoop
aio_gnutls_transport.GnutlsObject TLS connection state object ssl.SSLObject
aio_gnutls_transport.GnutlsHandshakeProtocol asyncio protocol implementing the TLS handshake
aio_gnutls_transport.GnutlsTransport asyncio transport over GnuTLS asyncio.sslproto._SSLProtocolTransport
aio_gnutls_transport.ssl the ssl compatibility module ssl

Caveats

The aio_gnutls_transport.ssl compatibility module provides only a subset of the native ssl stdlib module.

Achieving 100% compatibility is a non-goal (it would not be realistic since the native module is tightly coupled with OpenSSL).

Instead we take a minimalist and conservative approach: aio_gnutls_transport only supports the most common features and any attempt to use an unsupported attribute/method raises NotImplementedError.

The ssl module currently provides the following definitions:

ssl.SSLContext
ssl.create_default_context()

ssl.CERT_NONE
ssl.CERT_OPTIONAL
ssl.CERT_REQUIRED
ssl.Purpose
ssl.VerifyMode
ssl.DER_cert_to_PEM_cert
ssl.PEM_cert_to_DER_cert

and SSLContext supports the following attributes/methods:

SSLContext.check_hostname
SSLContext.load_cert_chain()
SSLContext.load_verify_locations()
SSLContext.load_default_certs()
SSLContext.verify_mode

Also, be aware that:

  • Errors are reported as aio_gnutls_transport.GnutlsError is not compatible with the native ssl.SSLError class (through they both derive from OSError).

  • aio_gnutls_transport.ssl.SSLContext derives from ssl.SSLContext, but they do not share their implementation. This is necessary to enable interoperability with 3rd-party libraries (eg: aiohttp) that enforce strict type checking.

Metadata

Release files for aio-gnutls-transport 0.3.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aio-gnutls-transport 0.3.1
File Size Uploaded
aio_gnutls_transport-0.3.1.tar.gz 25.3 kB Details

Release files / aio_gnutls_transport-0.3.1.tar.gz

Download URL aio_gnutls_transport-0.3.1.tar.gz
Size 25.3 kB
Tags Source
SHA-256 checksum
How to use checksums
50c0ddaac54d0fcb98a42e477064ac6d6cf49bd472c5cd034696f1ff8ab68916
BLAKE2b-256 checksum
How to use checksums
113bb5d01697a29330e1e1c3366f52e2fd633301f1a17ed3048483c78f58b0bc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.13.0 pkginfo/1.4.2 requests/2.21.0 setuptools/40.8.0 requests-toolbelt/0.8.0 tqdm/4.28.1 CPython/3.7.3

Release history Release notifications | RSS feed

This release

0.3.1 This release

1 release file

0.3.0

1 release file

0.2.1

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page