FULL HTML Documentation: http://jamercee.github.io/signet/
Signet provides support for building and delivering tamper resistant python to your users and customers.
Signet creates a custom python loader which you deliver with your script. On each invocation, the loader will verify no tampering has ocurred before it runs the python script.
Users have the confidence of knowing their scripts are safe and yet retain full access to the python source for code review and enhancement. And you know your users are running the right version of code.
Signet is fully integrated with distutils to make the process of building and installing new python projects as simple and painless as possible.
How does it work?
Signet relies on the strength of cryptographic hash to reliably detect file modifications. Signet builds hashes of your script and all it’s dependencies. These hashes are incorporated into a custom python loader which will handle re-verifying the hashes before it will run your script.
If your script or any of it’s dependencies are tampered with, the loader will emit an error and exit. If everything matches, the loader will run your script.
Example usage
For example, if you had a simple script hello.py:
import os
print('hello from %s' % os.name)
And you deployed it with this simple setup.py:
from distutils.core import setup, Extension
from signet.command.build_signet import build_signet
setup(name = 'hello',
cmdclass = {'build_signet': build_signet, },
ext_modules = [Extension('hello', sources=['hello.py'])],
)
Build your loader:
python setup.py build_signet
On Windows you’ll have hello.exe and on Linux you’ll have hello.
The signet system also provides facilities for code signing:
from distutils.core import setup, Extension
from signet.command.build_signet import build_signet, sign_code
setup(name = 'hello',
cmdclass = {'build_signet': build_signet,
'sign_code': sign_code,
},
ext_modules = [Extension('hello', sources=['hello.py'])],
)
Build your loader:
python setup.py build_signet
python setup.py sign_code --savedpassword --pfx-file {path-to-pfx}
Installing Signet
Signet is hosted on github at https://github.com/jamercee/signet
Installation using git:
git clone https://github.com/jamercee/signet cd signet python setup.py install
Signet can also be installed with pip:
pip install signet
Features
Multiplatform: works under
Windows (32/64-bit)
Linux
FreeBSD
Integrated with Distutils
Protection from tampering (SHA1 hashed content)
On Windows
Provides code signing executables
PE executable verification
Automatic resource file generation
Customizable program icon
Customizable python loader (full c++ included)
Unique process name
show hello rather than python hello.py
Compatible with virtualenv
Metadata
Release files for signet 3.0.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| signet-3.0.2.tar.gz | 32.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| signet-3.0.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 61.4 kB
Release files / signet-3.0.2.tar.gz
| Download URL | signet-3.0.2.tar.gz |
|---|---|
| Size | 32.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
62bb307911f33d701367fcede96b0b6730a628c33491854c141ff071587b1011
|
|
BLAKE2b-256 checksum How to use checksums |
5d158b59fe6db7b6ace00b222552f0cf10806dc1ccfa7ddddd81897f78154235
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/45.1.0 requests-toolbelt/0.9.1 tqdm/4.46.1 CPython/3.8.1
|
Release files / signet-3.0.2-py3-none-any.whl
| Download URL | signet-3.0.2-py3-none-any.whl |
|---|---|
| Size | 29.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b0c0f6d46a6ee83cea25d6f021c5058f9ebae7062dcdd0d418c3c30a7c23b47f
|
|
BLAKE2b-256 checksum How to use checksums |
0e9177f71959262a8fe9aa59c61f15be50bc162b78079b3f0c17fef4c5e4b98a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/45.1.0 requests-toolbelt/0.9.1 tqdm/4.46.1 CPython/3.8.1
|