Make an SSL context If *verify* is ``True``, the default, then certificate verification will occur using the standard CA roots. If *verify* is ``False``, then certificate verification will be disabled. If *verify* is a string which is a valid pathname, then if the pathname is a re
(
verify: bool | str = True,
check_hostname: bool = True,
alpns: list[str] | None = None,
)
| 1283 | |
| 1284 | |
| 1285 | def make_ssl_context( |
| 1286 | verify: bool | str = True, |
| 1287 | check_hostname: bool = True, |
| 1288 | alpns: list[str] | None = None, |
| 1289 | ) -> ssl.SSLContext: |
| 1290 | """Make an SSL context |
| 1291 | |
| 1292 | If *verify* is ``True``, the default, then certificate verification will occur using |
| 1293 | the standard CA roots. If *verify* is ``False``, then certificate verification will |
| 1294 | be disabled. If *verify* is a string which is a valid pathname, then if the |
| 1295 | pathname is a regular file, the CA roots will be taken from the file, otherwise if |
| 1296 | the pathname is a directory roots will be taken from the directory. |
| 1297 | |
| 1298 | If *check_hostname* is ``True``, the default, then the hostname of the server must |
| 1299 | be specified when connecting and the server's certificate must authorize the |
| 1300 | hostname. If ``False``, then hostname checking is disabled. |
| 1301 | |
| 1302 | *aplns* is ``None`` or a list of TLS ALPN (Application Layer Protocol Negotiation) |
| 1303 | strings to use in negotiation. For DNS-over-TLS, the right value is `["dot"]`. |
| 1304 | """ |
| 1305 | cafile, capath = dns._tls_util.convert_verify_to_cafile_and_capath(verify) |
| 1306 | ssl_context = ssl.create_default_context(cafile=cafile, capath=capath) |
| 1307 | # the pyright ignores below are because it gets confused between the |
| 1308 | # _no_ssl compatibility types and the real ones. |
| 1309 | ssl_context.minimum_version = ssl.TLSVersion.TLSv1_2 # type: ignore |
| 1310 | ssl_context.check_hostname = check_hostname |
| 1311 | if verify is False: |
| 1312 | ssl_context.verify_mode = ssl.CERT_NONE # type: ignore |
| 1313 | if alpns is not None: |
| 1314 | ssl_context.set_alpn_protocols(alpns) |
| 1315 | return ssl_context # type: ignore |
| 1316 | |
| 1317 | |
| 1318 | # for backwards compatibility |
no test coverage detected
searching dependent graphs…