Alex Stapleton | c5fffd3 | 2014-03-18 15:29:00 +0000 | [diff] [blame] | 1 | Frequently asked questions |
Alex Gaynor | de06b29 | 2014-02-18 16:40:09 -0800 | [diff] [blame] | 2 | ========================== |
| 3 | |
Paul Kehrer | c38e550 | 2017-06-19 00:54:12 -1000 | [diff] [blame] | 4 | ``cryptography`` failed to install! |
| 5 | ----------------------------------- |
| 6 | |
| 7 | If you are having issues installing ``cryptography`` the first troubleshooting |
| 8 | step is to upgrade ``pip`` and then try to install again. For most users this will |
| 9 | take the form of ``pip install -U pip``, but on Windows you should do |
| 10 | ``python -m pip install -U pip``. If you are still seeing errors after upgrading |
| 11 | and trying ``pip install cryptography`` again, please see the :doc:`/installation` |
| 12 | documentation. |
| 13 | |
Alex Gaynor | 59a6bc6 | 2014-02-18 18:13:48 -0800 | [diff] [blame] | 14 | How does ``cryptography`` compare to NaCl (Networking and Cryptography Library)? |
Alex Gaynor | de06b29 | 2014-02-18 16:40:09 -0800 | [diff] [blame] | 15 | -------------------------------------------------------------------------------- |
| 16 | |
| 17 | While ``cryptography`` and `NaCl`_ both share the goal of making cryptography |
| 18 | easier, and safer, to use for developers, ``cryptography`` is designed to be a |
Alex Gaynor | c37adab | 2014-02-18 16:46:58 -0800 | [diff] [blame] | 19 | general purpose library, interoperable with existing systems, while NaCl |
| 20 | features a collection of hand selected algorithms. |
Alex Gaynor | de06b29 | 2014-02-18 16:40:09 -0800 | [diff] [blame] | 21 | |
Alex Gaynor | 5809d48 | 2014-02-19 13:33:18 -0800 | [diff] [blame] | 22 | ``cryptography``'s :ref:`recipes <cryptography-layout>` layer has similar goals |
| 23 | to NaCl. |
Alex Gaynor | de06b29 | 2014-02-18 16:40:09 -0800 | [diff] [blame] | 24 | |
| 25 | If you prefer NaCl's design, we highly recommend `PyNaCl`_. |
| 26 | |
Paul Kehrer | f916dfc | 2017-05-27 14:24:28 -0500 | [diff] [blame] | 27 | Why use ``cryptography``? |
| 28 | ------------------------- |
| 29 | |
| 30 | If you've done cryptographic work in Python before you have likely encountered |
| 31 | other libraries in Python such as *M2Crypto*, *PyCrypto*, or *PyOpenSSL*. In |
| 32 | building ``cryptography`` we wanted to address a few issues we observed in the |
| 33 | legacy libraries: |
| 34 | |
| 35 | * Extremely error prone APIs and insecure defaults. |
| 36 | * Use of poor implementations of algorithms (i.e. ones with known side-channel |
| 37 | attacks). |
| 38 | * Lack of maintenance. |
| 39 | * Lack of high level APIs. |
| 40 | * Lack of PyPy and Python 3 support. |
Paul Kehrer | f916dfc | 2017-05-27 14:24:28 -0500 | [diff] [blame] | 41 | * Absence of algorithms such as |
| 42 | :class:`AES-GCM <cryptography.hazmat.primitives.ciphers.modes.GCM>` and |
| 43 | :class:`~cryptography.hazmat.primitives.kdf.hkdf.HKDF`. |
| 44 | |
Alex Gaynor | 0604944 | 2017-03-15 12:21:45 -0400 | [diff] [blame] | 45 | Compiling ``cryptography`` on macOS produces a ``fatal error: 'openssl/aes.h' file not found`` error |
| 46 | ---------------------------------------------------------------------------------------------------- |
Alex Gaynor | c77db59 | 2016-03-09 07:12:06 -0500 | [diff] [blame] | 47 | |
Alex Gaynor | 0604944 | 2017-03-15 12:21:45 -0400 | [diff] [blame] | 48 | This happens because macOS 10.11 no longer includes a copy of OpenSSL. |
Alex Gaynor | c77db59 | 2016-03-09 07:12:06 -0500 | [diff] [blame] | 49 | ``cryptography`` now provides wheels which include a statically linked copy of |
| 50 | OpenSSL. You're seeing this error because your copy of pip is too old to find |
| 51 | our wheel files. Upgrade your copy of pip with ``pip install -U pip`` and then |
| 52 | try install ``cryptography`` again. |
Alex Gaynor | 0fa997b | 2016-03-09 07:13:04 -0500 | [diff] [blame] | 53 | |
Alex Gaynor | e660ffe | 2017-04-09 09:19:02 -0400 | [diff] [blame] | 54 | If you are using PyPy, we do not currently ship ``cryptography`` wheels for |
| 55 | PyPy. You will need to install your own copy of OpenSSL -- we recommend using |
| 56 | Homebrew. |
| 57 | |
Paul Kehrer | fcf6fca | 2016-03-12 16:21:24 -0400 | [diff] [blame] | 58 | Starting ``cryptography`` using ``mod_wsgi`` produces an ``InternalError`` during a call in ``_register_osrandom_engine`` |
| 59 | ------------------------------------------------------------------------------------------------------------------------- |
| 60 | |
Paul Kehrer | 66a2372 | 2017-01-18 13:42:09 +0800 | [diff] [blame] | 61 | Upgrade to the latest ``cryptography`` and this issue should be resolved. |
Paul Kehrer | fcf6fca | 2016-03-12 16:21:24 -0400 | [diff] [blame] | 62 | |
| 63 | ``cryptography`` raised an ``InternalError`` and I'm not sure what to do? |
| 64 | ------------------------------------------------------------------------- |
| 65 | |
| 66 | Frequently ``InternalError`` is raised when there are errors on the OpenSSL |
| 67 | error stack that were placed there by other libraries that are also using |
| 68 | OpenSSL. Try removing the other libraries and see if the problem persists. |
Paul Kehrer | 4e9bd8c | 2016-03-12 16:33:39 -0400 | [diff] [blame] | 69 | If you have no other libraries using OpenSSL in your process, or they do not |
| 70 | appear to be at fault, it's possible that this is a bug in ``cryptography``. |
| 71 | Please file an `issue`_ with instructions on how to reproduce it. |
Paul Kehrer | fcf6fca | 2016-03-12 16:21:24 -0400 | [diff] [blame] | 72 | |
Paul Kehrer | bd7cd2d | 2017-02-13 20:01:06 -0600 | [diff] [blame] | 73 | Installing ``cryptography`` fails with ``ImportError: No module named setuptools_ext`` |
| 74 | -------------------------------------------------------------------------------------- |
| 75 | |
| 76 | Your ``cffi`` package is out of date. ``pip install -U cffi`` to update it. |
| 77 | |
Paul Kehrer | c7ecb45 | 2017-09-12 10:26:33 +0800 | [diff] [blame] | 78 | error: ``-Werror=sign-conversion``: No option ``-Wsign-conversion`` during installation |
| 79 | --------------------------------------------------------------------------------------- |
| 80 | |
| 81 | The compiler you are using is too old and not supported by ``cryptography``. |
| 82 | Please upgrade to a more recent version. If you are running OpenBSD 6.1 or |
| 83 | earlier the default compiler is extremely old. Use ``pkg_add`` to install a |
| 84 | newer ``gcc`` and then install ``cryptography`` using |
| 85 | ``CC=/path/to/newer/gcc pip install cryptography``. |
| 86 | |
Paul Kehrer | d0db04c | 2017-10-12 12:38:06 +0800 | [diff] [blame] | 87 | Installing ``cryptography`` fails with ``Invalid environment marker: python_version < '3'`` |
| 88 | ------------------------------------------------------------------------------------------- |
| 89 | |
| 90 | Your ``pip`` and/or ``setuptools`` are outdated. Please upgrade to the latest |
| 91 | versions with ``pip install -U pip setuptools`` (or on Windows |
| 92 | ``python -m pip install -U pip setuptools``). |
| 93 | |
Alex Gaynor | 0e8cdf1 | 2016-12-13 21:05:35 -0500 | [diff] [blame] | 94 | Installing cryptography with OpenSSL 0.9.8 or 1.0.0 fails |
| 95 | --------------------------------------------------------- |
Alex Gaynor | 29b2ebc | 2016-11-22 09:25:17 -0500 | [diff] [blame] | 96 | |
Alex Gaynor | 0e8cdf1 | 2016-12-13 21:05:35 -0500 | [diff] [blame] | 97 | The OpenSSL project has dropped support for the 0.9.8 and 1.0.0 release series. |
| 98 | Since they are no longer receiving security patches from upstream, |
| 99 | ``cryptography`` is also dropping support for them. To fix this issue you |
| 100 | should upgrade to a newer version of OpenSSL (1.0.1 or later). This may require |
| 101 | you to upgrade to a newer operating system. |
Alex Gaynor | 5d38206 | 2016-03-19 12:02:14 -0400 | [diff] [blame] | 102 | |
Alex Gaynor | 0fa997b | 2016-03-09 07:13:04 -0500 | [diff] [blame] | 103 | .. _`NaCl`: https://nacl.cr.yp.to/ |
Alex Gaynor | 988df9b | 2016-04-28 10:57:16 -0400 | [diff] [blame] | 104 | .. _`PyNaCl`: https://pynacl.readthedocs.io |
| 105 | .. _`WSGIApplicationGroup`: https://modwsgi.readthedocs.io/en/develop/configuration-directives/WSGIApplicationGroup.html |
Paul Kehrer | 4e9bd8c | 2016-03-12 16:33:39 -0400 | [diff] [blame] | 106 | .. _`issue`: https://github.com/pyca/cryptography/issues |