Skip to main content
https://travis-ci.org/SkierPGP/python-pgp.svg?branch=master https://coveralls.io/repos/SkierPGP/python-pgp/badge.png

Summary

python-pgp aims to reproduce the full functionality of GnuPG in Python. It may also be used for creating raw OpenPGP packets and packet streams for test purposes. This may be a bit of a heavyweight solution for some purposes.

This is a fork of the original library - the original one does not seem to be active and/or have a PyPI package.

Alternatives

Other Python packages which provide related functionality:

  • pyassuan - communicate with GnuPG using its socket protocol.

  • pgpdump - a pure python library for parsing OpenPGP packets.

  • gnupg - a wrapper around the GnuPG executable.

  • python-gnupg - another wrapper around the GnuPG executable.

  • gpgkeys - another wrapper around the GnuPG executable.

  • gpglib - a pure python library for parsing OpenPGP packets and decrypting messages.

  • OpenPGP - an unmaintained pure python library with much of the functionality of old versions of GnuPG.

  • encryptedfile - a pure python library for symmetrically encrypting files in an OpenPGP-compatible way.

  • PGPy - a pure python library with basic parsing and signing of OpenPGP packets.

  • OpenPGP-Python - a pure python port of openpgp-php. It can parse OpenPGP packets and verify & create signatures.

System requirements

  • build-essential

For Twofish support

  • libtwofish-dev

Installation

pip install pgp

with Twofish support:

pip install pgp[twofish]

with Camellia support:

pip install pgp[camellia]

with Twofish & Camellia support:

pip install pgp[camellia,twofish]

Usage

High level

Parsing a message

from pgp import read_message
message = read_message(data)

Parsing a transferrable key

from pgp import read_key
key = read_key(data)

Loading the GnuPG database

from pgp import get_gnupg_db
db = get_gnupg_db()
key = db.search(user_id='Joe')[0]

Retrieving a key from a keyserver and creating a message for it

>>> import datetime
>>> from pgp import *
>>> from pgp.keyserver import get_keyserver
>>> ks = get_keyserver('hkp://pgp.mit.edu/')
>>> results = ks.search('Joe Bloggs')
>>> recipient_key = results[0].get()
>>> message = message.TextMessage(
...     u"This message was encrypted using Python PGP",
...     datetime.datetime.now())
>>> my_secret_key = read_key_file('secret_key.gpg')
>>> my_secret_key.unlock('My passphrase')
>>> message = message.sign(my_secret_key)
>>> message = message.compress(2)  # Compression algorithm 2
>>> message = message.public_key_encrypt(9, recipient_key)
>>> message_packets = message.to_packets()
>>> message_data = b''.join(map(bytes, message_packets))
>>> armored_message = armor.ASCIIArmor(
...     armor.PGP_MESSAGE, message_data)
>>> file_handle = open('message.asc', 'w')
>>> file_handle.write(str(armored_message))
>>> file_handle.close()

Low level

Parsing a packet stream

from pgp.packets import parsers
parsers.parse_binary_packet_data(packet_data)

Serializing a packet

from pgp.packets import parsers
packets = parsers.parse_binary_packet_data(packet_data)
b''.join(map(bytes, packets))

Security

If you are using this package to handle private key data and decryption, please note that there is no (reasonable) way currently in Python to securely erase memory and that copies of things are made often and in non-obvious ways. If you are concerned about key data being compromised by a memory leak, do not use this package for handling secret key data. On the other hand, “if your memory is constantly being compromised, I would re-think your security setup.”

OpenPGP uses compression algorithms. Beware when feeding untrusted data into this library of Zip bomb or similar denial of service attacks.

Development

The main repository for this package is on GitHub. To develop on the package and install development dependencies, clone the repository and install the ‘dev’ extras.:

git clone git@github.com:mitchellrj/python-pgp.git
cd python-pgp
virtualenv .
bin/pip install -e ".[dev]"

Running tests

bin/python setup.py nosetests

Building documentation

bin/python setup.py build_sphinx

License

Copyright (C) 2014 Richard Mitchell

This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.

This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with this program. If not, see <http://www.gnu.org/licenses/>.

Metadata

Release files for py-pgp 0.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for py-pgp 0.0.1
File Size Uploaded
py-pgp-0.0.1.tar.gz 126.0 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for py-pgp 0.0.1
File
py_pgp-0.0.1-py3.4.egg Legacy Egg format - - Details
py_pgp-0.0.1-py3.3.egg Legacy Egg format - - Details
py_pgp-0.0.1-py3.2.egg Legacy Egg format - - Details
py_pgp-0.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 1.4 MB

Release files / py-pgp-0.0.1.tar.gz

Download URL py-pgp-0.0.1.tar.gz
Size 126.0 kB
Tags Source
SHA-256 checksum
How to use checksums
cad3611491598d1111a8abe0ebe5aa55119353bd8f7c78f623c16d131d3b85fc
BLAKE2b-256 checksum
How to use checksums
63d142ae81ae33db41b7474df650c71ea7648a14477a8103d53c974c872a24b8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / py_pgp-0.0.1-py3.4.egg

Download URL py_pgp-0.0.1-py3.4.egg
Size 375.8 kB
Tags Egg
SHA-256 checksum
How to use checksums
1c683e4cbae84f4f5500714493bbdb2845238bd4860e61cb5485b7a1094fd14f
BLAKE2b-256 checksum
How to use checksums
66ad8da6e200632a3232ae59f0ef7bd24a611263fb20cc6028f31923158b10ca
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / py_pgp-0.0.1-py3.3.egg

Download URL py_pgp-0.0.1-py3.3.egg
Size 381.9 kB
Tags Egg
SHA-256 checksum
How to use checksums
ed96b27acf35ff69c8902364594429eb0d83e95bec5157b544fc21630af4d5eb
BLAKE2b-256 checksum
How to use checksums
b28847f5a918c196f2b956c22d493f6f1ca1827d8f3ecd81d602139045f99aa7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / py_pgp-0.0.1-py3.2.egg

Download URL py_pgp-0.0.1-py3.2.egg
Size 295.3 kB
Tags Egg
SHA-256 checksum
How to use checksums
3bf921781fdef4b8a9bc83cf2a76782cbd3446b4c96e4f4d2edb81821b8bad4d
BLAKE2b-256 checksum
How to use checksums
3abbc77504dfa1847310182f3c165ef08256c1819a1325040ef2fffd6ad1ba70
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / py_pgp-0.0.1-py3-none-any.whl

Download URL py_pgp-0.0.1-py3-none-any.whl
Size 172.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e3d2b7bdf73d8e97cca12abad484df4d14d6b08da206f9547b839ff702a4ff83
BLAKE2b-256 checksum
How to use checksums
473a13a9d55dabdb316d82017014553e97ebc11e833c07615a5b24930acf01ae
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

0.0.1 This release

5 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page