Skip to content

Commit f290bf9

Browse files
committed
Doc: document OpenSSL 3 behaviour of the ssl module
- Describe the supported OpenSSL range (1.0.2 - 3.x) and the behaviour differences with OpenSSL 3: TLS 1.0/1.1 need a lowered security level, version-pinned PROTOCOL_TLSv1* contexts (and that, as before, they override a system-wide MinProtocol), OP_IGNORE_UNEXPECTED_EOF being on by default, and load_dh_params() errors coming from OSSL_DECODER. - OP_IGNORE_UNEXPECTED_EOF: say that it is enabled by default, explain the truncation risk and how to turn it off, and fix the "versionadded:: 3.10" which is wrong for this backport. - Add a NEWS entry summarising the OpenSSL 3 API port. - ignore false-positive :ALL markup warning in susp-ignored.csv Patch: python36-OpenSSL-32-documentation.patch
1 parent bc02344 commit f290bf9

3 files changed

Lines changed: 42 additions & 2 deletions

File tree

‎Doc/library/ssl.rst‎

Lines changed: 35 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,26 @@ probably additional platforms, as long as OpenSSL is installed on that platform.
2828
cause variations in behavior. For example, TLSv1.1 and TLSv1.2 come with
2929
openssl version 1.0.1.
3030

31+
.. note::
32+
33+
This build of the module requires OpenSSL 1.0.2 or newer and supports
34+
OpenSSL 3. When built against OpenSSL 3, only the OpenSSL 3.0 API is
35+
used. Notable differences with OpenSSL 3:
36+
37+
* OpenSSL 3 refuses TLS 1.0 and TLS 1.1 at the default security level.
38+
:data:`PROTOCOL_TLSv1` and :data:`PROTOCOL_TLSv1_1` contexts only
39+
work after lowering it, e.g. with
40+
``context.set_ciphers("@SECLEVEL=0:ALL")``.
41+
* :data:`PROTOCOL_TLSv1`, :data:`PROTOCOL_TLSv1_1` and
42+
:data:`PROTOCOL_TLSv1_2` contexts are created from the generic TLS
43+
method with both the minimum and maximum protocol version set to the
44+
requested version. Like the version-specific methods used with
45+
older OpenSSL, this overrides a ``MinProtocol`` set in the system-wide
46+
OpenSSL configuration.
47+
* :data:`OP_IGNORE_UNEXPECTED_EOF` is enabled by default.
48+
* Errors from :meth:`SSLContext.load_dh_params` are reported by the
49+
``OSSL_DECODER`` library instead of ``PEM``.
50+
3151
.. warning::
3252
Don't use this module without reading the :ref:`ssl-security`. Doing so
3353
may lead to a false sense of security, as the default settings of the
@@ -846,11 +866,24 @@ Constants
846866

847867
.. data:: OP_IGNORE_UNEXPECTED_EOF
848868

849-
Ignore unexpected shutdown of TLS connections.
869+
Ignore unexpected shutdown of TLS connections: an EOF from the peer
870+
without a TLS ``close_notify`` alert is treated like a regular
871+
shutdown instead of raising :exc:`SSLEOFError`. This mirrors the
872+
behaviour of OpenSSL 1.1.1 and is enabled by default on every
873+
:class:`SSLContext`.
874+
875+
.. warning::
876+
877+
With this option an attacker able to close the connection can
878+
truncate the data stream without being detected. Protocols that do
879+
not delimit their messages themselves (e.g. HTTP/1.0 responses
880+
without ``Content-Length``) should clear it:
881+
``context.options &= ~ssl.OP_IGNORE_UNEXPECTED_EOF``.
850882

851883
This option is only available with OpenSSL 3.0.0 and later.
852884

853-
.. versionadded:: 3.10
885+
.. versionadded:: 3.6.15
886+
Backported for OpenSSL 3 support (added in Python 3.10).
854887

855888
.. data:: HAS_ALPN
856889

‎Doc/tools/susp-ignored.csv‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -211,6 +211,7 @@ library/sqlite3,,:age,"cur.execute(""select * from people where name_last=:who a
211211
library/sqlite3,,:memory,
212212
library/sqlite3,,:who,"cur.execute(""select * from people where name_last=:who and age=:age"", {""who"": who, ""age"": age})"
213213
library/sqlite3,,:path,"db = sqlite3.connect('file:path/to/database?mode=ro', uri=True)"
214+
library/ssl,,:ALL,"context.set_ciphers(""@SECLEVEL=0:ALL"")"
214215
library/ssl,,:My,"Organizational Unit Name (eg, section) []:My Group"
215216
library/ssl,,:My,"Organization Name (eg, company) [Internet Widgits Pty Ltd]:My Organization, Inc."
216217
library/ssl,,:myserver,"Common Name (eg, YOUR name) []:myserver.mygroup.myorganization.com"
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
The :mod:`ssl` and :mod:`hashlib` modules build against OpenSSL 1.0.2
2+
through 3.x. When built against OpenSSL 3 they use only the OpenSSL 3.0
3+
API: version-specific TLS methods, ``DH``/``EC_KEY`` parameter handling,
4+
``RAND_pseudo_bytes()`` and other deprecated functions are replaced, and
5+
digests are fetched from providers with ``EVP_MD_fetch()``. Certificate
6+
verification errors now include the reason for the failure.

0 commit comments

Comments
 (0)