Skip to main content

Wassima 🔒

I named this library after my wife, whom I trust the most. ❤️

Download Count Total

This project offers you a great alternative to the MPL licensed certifi.

This project allows you to access your original operating system trust store, thus helping you to verify the remote peer certificates. It automatically fallback to an embedded trust store generated from the CCADB trusted source.

It works as-is out-of-the-box for any operating systems out there. Available on PyPy and Python 3.7+

✨ Installation

Using pip:

pip install wassima -U

Get started

A) Create a SSLContext

import wassima

ctx = wassima.create_default_ssl_context()
# ... The context magically contain your system root CAs, the rest is up to you!

B) Retrieve individually root CAs in a binary form (DER)

import wassima

certs = wassima.root_der_certificates()
# ... It contains a list of certificate represented in bytes

C) Retrieve individually root CAs in a string form (PEM)

import wassima

certs = wassima.root_pem_certificates()
# ... It contains a list of certificate represented in string

D) Retrieve a single bundle (concatenated) list of PEM certificates like certifi does

import wassima

bundle = wassima.generate_ca_bundle()
# ... It contains a string with all of your root CAs!
# It is not a path but the file content itself.

E) Register your own CA in addition to the system's

import wassima

# register CA only accept string PEM (one at a time!)
wassima.register_ca(open("./myrootca.pem", "r").read())
bundle = wassima.generate_ca_bundle()
# ... It contains a string with all of your root CAs, PLUS your own 'myrootca.pem'.
# It is not a path but the file content itself.

F) Use a hybrid trust store (OS + embedded CCADB bundle)

import wassima

# By default, only your OS trust store is used (with the embedded CCADB
# bundle as a fallback when the OS exposes nothing). Pass `hybrid_store=True`
# to force concatenating the embedded CCADB bundle in addition to the OS
# trust store. Useful in containers or appliances that ship with a slim or
# outdated system trust store.
ctx = wassima.create_default_ssl_context(hybrid_store=True)

# Available on every public top-level entry point:
wassima.root_der_certificates(hybrid_store=True)
wassima.root_pem_certificates(hybrid_store=True)
wassima.generate_ca_bundle(hybrid_store=True)

On Linux/BSD, when the system trust store has not been updated for at least 3 years, hybrid_store=True is implicitly applied so that the result is never silently outdated.

The output of root_der_certificates() (and the upper helpers built on top of it) is always deduplicated: a given DER certificate is guaranteed to appear at most once in the resulting list, regardless of how many OS stores or directories it lives in.

⏱️ Cache invalidation

For performance reasons the result of root_der_certificates() / root_pem_certificates() is cached. By default, the cache automatically expires every 12 hours so that any change to the OS trust store (e.g. a CA rotated overnight by your IT department) is picked up without having to restart the process.

You can override the TTL at runtime, pass 0 to disable caching entirely:

import wassima

# Force a refresh every hour:
wassima.set_cache_ttl(3600)

# Disable caching (every call recomputes):
wassima.set_cache_ttl(0)

# Restore the default (12 hours):
wassima.set_cache_ttl(wassima.DEFAULT_CACHE_TTL_SECONDS)

Setting a new TTL invalidates any pending cached result immediately.

Release files for wassima 2.1.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for wassima 2.1.4
File Size Uploaded
wassima-2.1.4.tar.gz 143.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for wassima 2.1.4
File Interpreter ABI Platform
wassima-2.1.4-py3-none-any.whl Python 3 none any Details

Total release size: 277.8 kB

Release files / wassima-2.1.4.tar.gz

Download URL wassima-2.1.4.tar.gz
Size 143.5 kB
Tags Source
SHA-256 checksum
How to use checksums
21bb77253bb8032c05393172c4d2df395f423b7e704538f3b2407f50c032034d
BLAKE2b-256 checksum
How to use checksums
5f92fe256733440f7c36084ce924f373fbbf709277ddf92262b2295e8caf26d5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 27, 2026.

Transparency log

Release files / wassima-2.1.4-py3-none-any.whl

Download URL wassima-2.1.4-py3-none-any.whl
Size 134.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
26022272d4618aada0e26df2e79dbc0e034be8be9d6d5396512690ffc6a94e7b
BLAKE2b-256 checksum
How to use checksums
561d032b95952208fa3e623d54efb650bf0a134e2a02e7400b36c63363c27b74
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 27, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

2.1.4 This release

2 release files

2.1.3

2 release files

2.1.2

2 release files

2.1.1

2 release files

2.1.0

2 release files

2.0.6

2 release files

2.0.5

2 release files

2.0.4

2 release files

2.0.3

2 release files

2.0.2

2 release files

2.0.1

2 release files

2.0.0

2 release files

1.2.1

78 release files

1.2.0

77 release files

1.1.6

76 release files

1.1.5

78 release files

1.1.4

78 release files

1.1.2

78 release files

1.1.1

78 release files

1.1.0

67 release files

1.0.3

67 release files

1.0.1

67 release files

1.0.0

46 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page