| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 1 | # Wrapper module for _ssl, providing some additional facilities | 
 | 2 | # implemented in Python.  Written by Bill Janssen. | 
 | 3 |  | 
 | 4 | """\ | 
 | 5 | This module provides some more Pythonic support for SSL. | 
 | 6 |  | 
 | 7 | Object types: | 
 | 8 |  | 
 | 9 |   sslsocket -- subtype of socket.socket which does SSL over the socket | 
 | 10 |  | 
 | 11 | Exceptions: | 
 | 12 |  | 
 | 13 |   sslerror -- exception raised for I/O errors | 
 | 14 |  | 
 | 15 | Functions: | 
 | 16 |  | 
 | 17 |   cert_time_to_seconds -- convert time string used for certificate | 
 | 18 |                           notBefore and notAfter functions to integer | 
 | 19 |                           seconds past the Epoch (the time values | 
 | 20 |                           returned from time.time()) | 
 | 21 |  | 
 | 22 |   fetch_server_certificate (HOST, PORT) -- fetch the certificate provided | 
 | 23 |                           by the server running on HOST at port PORT.  No | 
 | 24 |                           validation of the certificate is performed. | 
 | 25 |  | 
 | 26 | Integer constants: | 
 | 27 |  | 
 | 28 | SSL_ERROR_ZERO_RETURN | 
 | 29 | SSL_ERROR_WANT_READ | 
 | 30 | SSL_ERROR_WANT_WRITE | 
 | 31 | SSL_ERROR_WANT_X509_LOOKUP | 
 | 32 | SSL_ERROR_SYSCALL | 
 | 33 | SSL_ERROR_SSL | 
 | 34 | SSL_ERROR_WANT_CONNECT | 
 | 35 |  | 
 | 36 | SSL_ERROR_EOF | 
 | 37 | SSL_ERROR_INVALID_ERROR_CODE | 
 | 38 |  | 
 | 39 | The following group define certificate requirements that one side is | 
 | 40 | allowing/requiring from the other side: | 
 | 41 |  | 
 | 42 | CERT_NONE - no certificates from the other side are required (or will | 
 | 43 |             be looked at if provided) | 
 | 44 | CERT_OPTIONAL - certificates are not required, but if provided will be | 
 | 45 |                 validated, and if validation fails, the connection will | 
 | 46 |                 also fail | 
 | 47 | CERT_REQUIRED - certificates are required, and will be validated, and | 
 | 48 |                 if validation fails, the connection will also fail | 
 | 49 |  | 
 | 50 | The following constants identify various SSL protocol variants: | 
 | 51 |  | 
 | 52 | PROTOCOL_SSLv2 | 
 | 53 | PROTOCOL_SSLv3 | 
 | 54 | PROTOCOL_SSLv23 | 
 | 55 | PROTOCOL_TLSv1 | 
 | 56 | """ | 
 | 57 |  | 
 | 58 | import os, sys | 
 | 59 |  | 
 | 60 | import _ssl             # if we can't import it, let the error propagate | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 61 | from _ssl import sslerror | 
 | 62 | from _ssl import CERT_NONE, CERT_OPTIONAL, CERT_REQUIRED | 
 | 63 | from _ssl import PROTOCOL_SSLv2, PROTOCOL_SSLv3, PROTOCOL_SSLv23, PROTOCOL_TLSv1 | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 64 | from _ssl import \ | 
 | 65 |      SSL_ERROR_ZERO_RETURN, \ | 
 | 66 |      SSL_ERROR_WANT_READ, \ | 
 | 67 |      SSL_ERROR_WANT_WRITE, \ | 
 | 68 |      SSL_ERROR_WANT_X509_LOOKUP, \ | 
 | 69 |      SSL_ERROR_SYSCALL, \ | 
 | 70 |      SSL_ERROR_SSL, \ | 
 | 71 |      SSL_ERROR_WANT_CONNECT, \ | 
 | 72 |      SSL_ERROR_EOF, \ | 
 | 73 |      SSL_ERROR_INVALID_ERROR_CODE | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 74 |  | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 75 | from socket import socket | 
 | 76 | from socket import getnameinfo as _getnameinfo | 
 | 77 |  | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 78 |  | 
 | 79 | class sslsocket (socket): | 
 | 80 |  | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 81 |     """This class implements a subtype of socket.socket that wraps | 
 | 82 |     the underlying OS socket in an SSL context when necessary, and | 
 | 83 |     provides read and write methods over that channel.""" | 
 | 84 |  | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 85 |     def __init__(self, sock, keyfile=None, certfile=None, | 
 | 86 |                  server_side=False, cert_reqs=CERT_NONE, | 
 | 87 |                  ssl_version=PROTOCOL_SSLv23, ca_certs=None): | 
 | 88 |         socket.__init__(self, _sock=sock._sock) | 
 | 89 |         if certfile and not keyfile: | 
 | 90 |             keyfile = certfile | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 91 |         # see if it's connected | 
 | 92 |         try: | 
 | 93 |             socket.getpeername(self) | 
 | 94 |         except: | 
 | 95 |             # no, no connection yet | 
 | 96 |             self._sslobj = None | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 97 |         else: | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 98 |             # yes, create the SSL object | 
 | 99 |             self._sslobj = _ssl.sslwrap(self._sock, server_side, | 
 | 100 |                                         keyfile, certfile, | 
 | 101 |                                         cert_reqs, ssl_version, ca_certs) | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 102 |         self.keyfile = keyfile | 
 | 103 |         self.certfile = certfile | 
 | 104 |         self.cert_reqs = cert_reqs | 
 | 105 |         self.ssl_version = ssl_version | 
 | 106 |         self.ca_certs = ca_certs | 
 | 107 |  | 
 | 108 |     def read(self, len=1024): | 
| Bill Janssen | 24bccf2 | 2007-08-30 17:07:28 +0000 | [diff] [blame] | 109 |  | 
 | 110 |         """Read up to LEN bytes and return them. | 
 | 111 |         Return zero-length string on EOF.""" | 
 | 112 |  | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 113 |         return self._sslobj.read(len) | 
 | 114 |  | 
 | 115 |     def write(self, data): | 
| Bill Janssen | 24bccf2 | 2007-08-30 17:07:28 +0000 | [diff] [blame] | 116 |  | 
 | 117 |         """Write DATA to the underlying SSL channel.  Returns | 
 | 118 |         number of bytes of DATA actually transmitted.""" | 
 | 119 |  | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 120 |         return self._sslobj.write(data) | 
 | 121 |  | 
 | 122 |     def getpeercert(self): | 
| Bill Janssen | 24bccf2 | 2007-08-30 17:07:28 +0000 | [diff] [blame] | 123 |  | 
 | 124 |         """Returns a formatted version of the data in the | 
 | 125 |         certificate provided by the other end of the SSL channel. | 
 | 126 |         Return None if no certificate was provided, {} if a | 
 | 127 |         certificate was provided, but not validated.""" | 
 | 128 |  | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 129 |         return self._sslobj.peer_certificate() | 
 | 130 |  | 
 | 131 |     def send (self, data, flags=0): | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 132 |         if self._sslobj: | 
 | 133 |             if flags != 0: | 
 | 134 |                 raise ValueError( | 
 | 135 |                     "non-zero flags not allowed in calls to send() on %s" % | 
 | 136 |                     self.__class__) | 
 | 137 |             return self._sslobj.write(data) | 
 | 138 |         else: | 
 | 139 |             return socket.send(self, data, flags) | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 140 |  | 
 | 141 |     def send_to (self, data, addr, flags=0): | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 142 |         if self._sslobj: | 
 | 143 |             raise ValueError("send_to not allowed on instances of %s" % | 
 | 144 |                              self.__class__) | 
 | 145 |         else: | 
 | 146 |             return socket.send_to(self, data, addr, flags) | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 147 |  | 
 | 148 |     def sendall (self, data, flags=0): | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 149 |         if self._sslobj: | 
 | 150 |             if flags != 0: | 
 | 151 |                 raise ValueError( | 
 | 152 |                     "non-zero flags not allowed in calls to sendall() on %s" % | 
 | 153 |                     self.__class__) | 
 | 154 |             return self._sslobj.write(data) | 
 | 155 |         else: | 
 | 156 |             return socket.sendall(self, data, flags) | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 157 |  | 
 | 158 |     def recv (self, buflen=1024, flags=0): | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 159 |         if self._sslobj: | 
 | 160 |             if flags != 0: | 
 | 161 |                 raise ValueError( | 
 | 162 |                     "non-zero flags not allowed in calls to sendall() on %s" % | 
 | 163 |                     self.__class__) | 
 | 164 |             return self._sslobj.read(data, buflen) | 
 | 165 |         else: | 
 | 166 |             return socket.recv(self, buflen, flags) | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 167 |  | 
 | 168 |     def recv_from (self, addr, buflen=1024, flags=0): | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 169 |         if self._sslobj: | 
 | 170 |             raise ValueError("recv_from not allowed on instances of %s" % | 
 | 171 |                              self.__class__) | 
 | 172 |         else: | 
 | 173 |             return socket.recv_from(self, addr, buflen, flags) | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 174 |  | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 175 |     def ssl_shutdown(self): | 
| Bill Janssen | 24bccf2 | 2007-08-30 17:07:28 +0000 | [diff] [blame] | 176 |  | 
 | 177 |         """Shuts down the SSL channel over this socket (if active), | 
 | 178 |         without closing the socket connection.""" | 
 | 179 |  | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 180 |         if self._sslobj: | 
 | 181 |             self._sslobj.shutdown() | 
 | 182 |             self._sslobj = None | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 183 |  | 
 | 184 |     def shutdown(self, how): | 
 | 185 |         self.ssl_shutdown() | 
 | 186 |         socket.shutdown(self, how) | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 187 |  | 
 | 188 |     def close(self): | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 189 |         self.ssl_shutdown() | 
 | 190 |         socket.close(self) | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 191 |  | 
 | 192 |     def connect(self, addr): | 
| Bill Janssen | 24bccf2 | 2007-08-30 17:07:28 +0000 | [diff] [blame] | 193 |  | 
 | 194 |         """Connects to remote ADDR, and then wraps the connection in | 
 | 195 |         an SSL channel.""" | 
 | 196 |  | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 197 |         # Here we assume that the socket is client-side, and not | 
 | 198 |         # connected at the time of the call.  We connect it, then wrap it. | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 199 |         if self._sslobj: | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 200 |             raise ValueError("attempt to connect already-connected sslsocket!") | 
 | 201 |         socket.connect(self, addr) | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 202 |         self._sslobj = _ssl.sslwrap(self._sock, False, self.keyfile, self.certfile, | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 203 |                                     self.cert_reqs, self.ssl_version, | 
 | 204 |                                     self.ca_certs) | 
 | 205 |  | 
 | 206 |     def accept(self): | 
| Bill Janssen | 24bccf2 | 2007-08-30 17:07:28 +0000 | [diff] [blame] | 207 |  | 
 | 208 |         """Accepts a new connection from a remote client, and returns | 
 | 209 |         a tuple containing that new connection wrapped with a server-side | 
 | 210 |         SSL channel, and the address of the remote client.""" | 
 | 211 |  | 
| Bill Janssen | 426ea0a | 2007-08-29 22:35:05 +0000 | [diff] [blame] | 212 |         newsock, addr = socket.accept(self) | 
 | 213 |         return (sslsocket(newsock, True, self.keyfile, self.certfile, | 
 | 214 |                          self.cert_reqs, self.ssl_version, | 
 | 215 |                          self.ca_certs), addr) | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 216 |  | 
 | 217 |  | 
 | 218 | # some utility functions | 
 | 219 |  | 
 | 220 | def cert_time_to_seconds(cert_time): | 
| Bill Janssen | 24bccf2 | 2007-08-30 17:07:28 +0000 | [diff] [blame] | 221 |  | 
 | 222 |     """Takes a date-time string in standard ASN1_print form | 
 | 223 |     ("MON DAY 24HOUR:MINUTE:SEC YEAR TIMEZONE") and return | 
 | 224 |     a Python time value in seconds past the epoch.""" | 
 | 225 |  | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 226 |     import time | 
 | 227 |     return time.mktime(time.strptime(cert_time, "%b %d %H:%M:%S %Y GMT")) | 
 | 228 |  | 
 | 229 | # a replacement for the old socket.ssl function | 
 | 230 |  | 
 | 231 | def sslwrap_simple (sock, keyfile=None, certfile=None): | 
 | 232 |  | 
| Bill Janssen | 24bccf2 | 2007-08-30 17:07:28 +0000 | [diff] [blame] | 233 |     """A replacement for the old socket.ssl function.  Designed | 
 | 234 |     for compability with Python 2.5 and earlier.  Will disappear in | 
 | 235 |     Python 3.0.""" | 
 | 236 |  | 
| Guido van Rossum | 4f2c3dd | 2007-08-25 15:08:43 +0000 | [diff] [blame] | 237 |     return _ssl.sslwrap(sock._sock, 0, keyfile, certfile, CERT_NONE, | 
 | 238 |                         PROTOCOL_SSLv23, None) |