Certifi is a carefully curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. It has been extracted from the Requests project.
Installation
certifi is available on PyPI. Simply install it with pip:
$ pip install certifi
Usage
To reference the installed certificate authority (CA) bundle, you can use the built-in function:
>>> import certifi >>> certifi.where() '/usr/local/lib/python2.7/site-packages/certifi/cacert.pem'
Enjoy!
1024-bit Root Certificates
Browsers and certificate authorities have concluded that 1024-bit keys are unacceptably weak for certificates, particularly root certificates. For this reason, Mozilla has removed any weak (i.e. 1024-bit key) certificate from its bundle, replacing it with an equivalent strong (i.e. 2048-bit or greater key) certificate from the same CA. Because Mozilla removed these certificates from its bundle, certifi removed them as well.
Unfortunately, old versions of OpenSSL (less than 1.0.2) sometimes fail to validate certificate chains that use the strong roots. For this reason, if you fail to validate a certificate using the certifi.where() mechanism, you can intentionally re-add the 1024-bit roots back into your bundle by calling certifi.old_where() instead. This is not recommended in production: if at all possible you should upgrade to a newer OpenSSL. However, if you have no other option, this may work for you.
Release files for certifi 2017.4.17
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| certifi-2017.4.17.tar.gz | 373.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| certifi-2017.4.17-py2.py3-none-any.whl | Python 2, Python 3 | none | any | Details |
Total release size: 749.4 kB
Release files / certifi-2017.4.17.tar.gz
| Download URL | certifi-2017.4.17.tar.gz |
|---|---|
| Size | 373.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f7527ebf7461582ce95f7a9e03dd141ce810d40590834f4ec20cddd54234c10a
|
|
BLAKE2b-256 checksum How to use checksums |
dd0e1e3b58c861d40a9ca2d7ea4ccf47271d4456ae4294c5998ad817bd1b4396
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
Release files / certifi-2017.4.17-py2.py3-none-any.whl
| Download URL | certifi-2017.4.17-py2.py3-none-any.whl |
|---|---|
| Size | 375.9 kB |
| Tags | Python 2 Python 3 |
|
SHA-256 checksum How to use checksums |
f4318671072f030a33c7ca6acaef720ddd50ff124d1388e50c1bda4cbd6d7010
|
|
BLAKE2b-256 checksum How to use checksums |
eb01c1f58987b777d6c4ec535b4e004a4a07bfc9db06f0c7533367ca6da8f2a6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |