Skip to main content

Python library and CLI for Domain-based Integrity Verification Enforcement (DIVE)

Project description

OpenDIVE: Python Client for Domain-based Integrity Verification Enforcement (DIVE)

License: MIT Python: 3.8+ Version: 0.1.0 Status: Alpha

OpenDIVE is a Python client library for the DIVE protocol (Domain-based Integrity Verification Enforcement), a cryptographic protocol that leverages DNSSEC to verify the integrity and authenticity of web resources. DIVE operates as an additional security layer above HTTP/HTTPS, ensuring that resources are signed and validated against DNS-published keys.


Features

  • DNSSEC-backed verification: Uses DNS TXT records (_dive, _divekey) to publish policies and public keys.
  • Cryptographic signatures: Supports Ed25519 and Ed448 for signing, and SHA-256/384/512 for hashing.
  • CLI tool: Includes commands for verification, key generation, signing, and DNS inspection.
  • Incremental deployment: Works alongside existing infrastructure without breaking non-DIVE clients.
  • Reporting: Sends verification failure reports to a configurable endpoint.

Installation

From PyPI (Alpha Release)

pip install opendive-client

From Source

git clone https://github.com/diveprotocol/opendive-client.git
cd opendive-client
pip install -e .

Dependencies

  • Python 3.8+
  • dnspython (DNSSEC resolution)
  • cryptography (Ed25519/Ed448 support)
  • httpx (HTTP client)
  • click (CLI)

Usage

CLI Commands

OpenDIVE provides a CLI for common operations:

# Verify a resource
opendive verify https://example.com/file.tar.gz

# Download a resource (only if DIVE verification passes)
opendive download https://example.com/file.tar.gz

# Generate a key pair
opendive keygen --alg ed25519 --key-id mykey --domain example.com

# Sign a file
opendive sign myfile.tar.gz --private-key <base64_private_key> --key-id mykey

# Inspect DNS records
opendive dns example.com --key-id mykey

Python Library

from dive.client import DiveClient

client = DiveClient(require_dnssec=True)
result = client.verify("https://example.com/file.tar.gz")

if result.accepted:
    print("Resource is authentic!")
else:
    print(f"DIVE rejected resource: {result.failure_reason}")

Documentation

DIVE Protocol

OpenDIVE API


Development

Running Tests

pytest tests/

Contributing

Pull requests are welcome! For major changes, please open an issue first.


License

MIT License. See LICENSE for details.


Security

For security issues, see SECURITY.md.


Contact

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

opendive_client-0.1.0.tar.gz (20.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

opendive_client-0.1.0-py3-none-any.whl (21.2 kB view details)

Uploaded Python 3

File details

Details for the file opendive_client-0.1.0.tar.gz.

File metadata

  • Download URL: opendive_client-0.1.0.tar.gz
  • Upload date:
  • Size: 20.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for opendive_client-0.1.0.tar.gz
Algorithm Hash digest
SHA256 49d59329b24f61409b91fb20f105e0117e5ba54455867c0aeb2ba7a120e53cb8
MD5 c12439f34557a49bae9e75d908d7b565
BLAKE2b-256 5a4b01c42e4691829db28ef3a40e1993ec2dc19b0251ff8f7332400a8ab6b2e8

See more details on using hashes here.

Provenance

The following attestation bundles were made for opendive_client-0.1.0.tar.gz:

Publisher: publish.yml on diveprotocol/opendive-client

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file opendive_client-0.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for opendive_client-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 eb5a1c4f1d8abf0e0098e981095225b4e0fef5c010de068db304fbb0acb29ff9
MD5 d17f3a0cb31cda0d4abae224fff7eb21
BLAKE2b-256 66a38ab64bc698bff87a064df0822457842592f3bdacc4c8adf1d704f747bfb7

See more details on using hashes here.

Provenance

The following attestation bundles were made for opendive_client-0.1.0-py3-none-any.whl:

Publisher: publish.yml on diveprotocol/opendive-client

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page