Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions CHANGELOG.rst
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,9 @@ Deprecations:
Changes:
^^^^^^^^

- Exported ``OpenSSL.SSL.FILETYPE_ASN1`` (and documented ``FILETYPE_PEM`` in
``SSL.__all__``) so the file-type constants match the SSL API documentation.
[`#1217 <https://github.com/pyca/pyopenssl/issues/1217>`_]
- Fixed a race in which an exception raised by a verify, ALPN selection, OCSP, or DTLS cookie callback for one ``Connection`` could be raised on an unrelated ``Connection`` created from the same ``Context`` and used concurrently from another thread. Exceptions from these callbacks are now tracked per ``Connection``. Discovered and reported by SecDim Security Research.
- Fixed exceptions raised by a verify callback registered with ``Connection.set_verify`` being swallowed instead of being propagated to the caller.

Expand Down
3 changes: 3 additions & 0 deletions src/OpenSSL/SSL.py
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@
text_to_bytes_and_warn as _text_to_bytes_and_warn,
)
from OpenSSL.crypto import (
FILETYPE_ASN1,
FILETYPE_PEM,
X509,
PKey,
Expand All @@ -60,6 +61,8 @@
"DTLS_CLIENT_METHOD",
"DTLS_METHOD",
"DTLS_SERVER_METHOD",
"FILETYPE_ASN1",
"FILETYPE_PEM",
"MODE_RELEASE_BUFFERS",
"NO_OVERLAPPING_PROTOCOLS",
"OPENSSL_BUILT_ON",
Expand Down
14 changes: 13 additions & 1 deletion tests/test_ssl.py
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@
from cryptography.x509.oid import NameOID
from pretend import raiser

from OpenSSL import SSL
from OpenSSL import SSL, crypto
from OpenSSL._util import ffi as _ffi
from OpenSSL._util import lib as _lib
from OpenSSL.crypto import (
Expand All @@ -67,6 +67,7 @@
)
from OpenSSL.SSL import (
DTLS_METHOD,
FILETYPE_ASN1,
NO_OVERLAPPING_PROTOCOLS,
OP_COOKIE_EXCHANGE,
OP_NO_COMPRESSION,
Expand Down Expand Up @@ -4119,6 +4120,17 @@ class TestConstants:
their values.
"""

def test_filetype_asn1(self) -> None:
"""
`OpenSSL.SSL.FILETYPE_ASN1` is exported and matches the crypto
constant documented for `use_certificate_file` /
`use_privatekey_file`.
"""
assert FILETYPE_ASN1 is SSL.FILETYPE_ASN1
assert FILETYPE_ASN1 == crypto.FILETYPE_ASN1
assert "FILETYPE_ASN1" in SSL.__all__
assert "FILETYPE_PEM" in SSL.__all__

@pytest.mark.skipif(
OP_NO_QUERY_MTU is None,
reason="OP_NO_QUERY_MTU unavailable - OpenSSL version may be too old",
Expand Down
Loading