Skip to main content
* Flask-TLSAuth

Flask-TLSAuth integrates a minimal certificate authority (CA) and
implements TLS client certificate authentication. It depends on nginx
for handling the TLS authentication part.

** Installation
#+BEGIN_SRC sh
pip install flask_tlsauth
#+END_SRC
Flask-TLSAuth depends on tlsauth which provides minimal tools to
act as a CA. Please follow the "CA and https service install" steps
from https://github.com/stef/tlsauth to set up your webserver and CA.

** tlsauth decorator
Flask-TLSAuth provides a simple decorator to guard your entry points:
#+BEGIN_SRC python
from flask import Flask, Response, redirect
import os
app = Flask(__name__)
app.secret_key = 'some secret randomness'

# we need a CA
from tlsauth import CertAuthority
import flask_tlsauth as tlsauth

# previously we setup up the CA according to the tlsauth doc
ca=CertAuthority('<path-to-ca>')

adminOs=['CA admins']
# grants admin access to anyone with a
# valid cert asserting membership in "CA admins"
tlsauth.tlsauth_init(app, ca, groups=adminOs)

def unauth():
return redirect("/")

@app.route('/hello')

# lets protect this valuable function,
# redirecting unauthorized visitors to /
@tlsauth.tlsauth(unauth=unauth, groups=adminOs)
def hello():
return Response("hello world")
#+END_SRC

** Managing certs
Flask-TLSAuth provides a few default routes to manage the certs and
the CA.

*** /tlsauth/register/
Visitors can register like on a normal site, but when done, they get a
PKCS12 certificate ready to be saved and imported in all
browsers. This is totally automatic and there's no check if the
specified organization is not a privileged one (like "CA admins" in
the above example). This really provides no security, for bots and
scripts it's even easier to use these certs than for normal humans.
Other mechanisms must be deployed to provide meaningful authentication.

*** /tlsauth/certify/
Visitors can submit their Certificate Signing Request (can be easily
generated using gencert.sh from tlsauth), which depending on
configuration either returns automatically a signed certificate (no
meaningful authentication this way, avoid this!), or it gets stored
for later approval by the "CA admins".

*** /tlsauth/cert/
Returns the CA root certificate in PEM format, for import into your browser.

*** /tlsauth/csrs/
Displays a list of incoming CSRs to any certified member of the "CA
admin" group. The certs can be either rejected or signed, in the later
case the resulting certificate is sent to the email address of the
subject.

*** /tlsauth/test/
Displays whether you are TLS authenticated and what your distinguished name is.

Release files for flask_tlsauth 0.1.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for flask_tlsauth 0.1.3
File Size Uploaded
flask_tlsauth-0.1.3.tar.gz 4.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for flask_tlsauth 0.1.3
File Interpreter ABI Platform
flask_tlsauth-0.1.3-py2.7.egg Legacy Egg format - - Details

Total release size: 13.5 kB

Release files / flask_tlsauth-0.1.3.tar.gz

Download URL flask_tlsauth-0.1.3.tar.gz
Size 4.3 kB
Tags Source
SHA-256 checksum
How to use checksums
e9df7391591f9bfe553c8c62b4471e0b756200ee1b4e2d3f732387e527ec4236
BLAKE2b-256 checksum
How to use checksums
d7ec9dbe881acebd59d24ab50ae07ac9a246d2b96db75552321119dc26070be1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / flask_tlsauth-0.1.3-py2.7.egg

Download URL flask_tlsauth-0.1.3-py2.7.egg
Size 9.2 kB
Tags Egg
SHA-256 checksum
How to use checksums
5940a7bbe3da511a7111b9f6f5010d06c0f08237d856fd2795238352a52cc4e8
BLAKE2b-256 checksum
How to use checksums
cbf233a3aef0059a4f2d2303d4d8b45ee8832cff251f9b1c0e6c21b8df567c6b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

0.1.3 This release

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page