From 751dea99017bd9f7cd97b6abc02d6d8a38cc3975 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Micha=C5=82=20Furga=C5=82a?= <83299832+00200200@users.noreply.github.com> Date: Wed, 30 Sep 2026 12:47:04 +0200 Subject: [PATCH] Export OpenSSL.SSL.FILETYPE_ASN1 to match documented API The SSL docs advertise FILETYPE_ASN1 for use_certificate_file and use_privatekey_file, but only FILETYPE_PEM was imported from crypto. Re-export both constants via SSL.__all__ and cover with a regression test. Fixes #1217 --- CHANGELOG.rst | 3 +++ src/OpenSSL/SSL.py | 3 +++ tests/test_ssl.py | 14 +++++++++++++- 3 files changed, 19 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.rst b/CHANGELOG.rst index a5d78efe..eab0b479 100644 --- a/CHANGELOG.rst +++ b/CHANGELOG.rst @@ -21,6 +21,9 @@ Deprecations: Changes: ^^^^^^^^ +- Exported ``OpenSSL.SSL.FILETYPE_ASN1`` (and documented ``FILETYPE_PEM`` in + ``SSL.__all__``) so the file-type constants match the SSL API documentation. + [`#1217 `_] - Fixed a race in which an exception raised by a verify, ALPN selection, OCSP, or DTLS cookie callback for one ``Connection`` could be raised on an unrelated ``Connection`` created from the same ``Context`` and used concurrently from another thread. Exceptions from these callbacks are now tracked per ``Connection``. Discovered and reported by SecDim Security Research. - Fixed exceptions raised by a verify callback registered with ``Connection.set_verify`` being swallowed instead of being propagated to the caller. diff --git a/src/OpenSSL/SSL.py b/src/OpenSSL/SSL.py index d91915bc..f73a7bd4 100644 --- a/src/OpenSSL/SSL.py +++ b/src/OpenSSL/SSL.py @@ -46,6 +46,7 @@ text_to_bytes_and_warn as _text_to_bytes_and_warn, ) from OpenSSL.crypto import ( + FILETYPE_ASN1, FILETYPE_PEM, X509, PKey, @@ -60,6 +61,8 @@ "DTLS_CLIENT_METHOD", "DTLS_METHOD", "DTLS_SERVER_METHOD", + "FILETYPE_ASN1", + "FILETYPE_PEM", "MODE_RELEASE_BUFFERS", "NO_OVERLAPPING_PROTOCOLS", "OPENSSL_BUILT_ON", diff --git a/tests/test_ssl.py b/tests/test_ssl.py index 1f4c4663..2c36c0bd 100644 --- a/tests/test_ssl.py +++ b/tests/test_ssl.py @@ -49,7 +49,7 @@ from cryptography.x509.oid import NameOID from pretend import raiser -from OpenSSL import SSL +from OpenSSL import SSL, crypto from OpenSSL._util import ffi as _ffi from OpenSSL._util import lib as _lib from OpenSSL.crypto import ( @@ -67,6 +67,7 @@ ) from OpenSSL.SSL import ( DTLS_METHOD, + FILETYPE_ASN1, NO_OVERLAPPING_PROTOCOLS, OP_COOKIE_EXCHANGE, OP_NO_COMPRESSION, @@ -4119,6 +4120,17 @@ class TestConstants: their values. """ + def test_filetype_asn1(self) -> None: + """ + `OpenSSL.SSL.FILETYPE_ASN1` is exported and matches the crypto + constant documented for `use_certificate_file` / + `use_privatekey_file`. + """ + assert FILETYPE_ASN1 is SSL.FILETYPE_ASN1 + assert FILETYPE_ASN1 == crypto.FILETYPE_ASN1 + assert "FILETYPE_ASN1" in SSL.__all__ + assert "FILETYPE_PEM" in SSL.__all__ + @pytest.mark.skipif( OP_NO_QUERY_MTU is None, reason="OP_NO_QUERY_MTU unavailable - OpenSSL version may be too old",