blob: 5ad00d03a05cdab7e24ed622ca0a0a9502eab8b9 [file] [log] [blame]
Alex Gaynoraf82d5e2013-10-29 17:07:24 -07001.. hazmat::
Alex Gaynor0f7f7812013-09-30 10:52:36 -07002
Alex Gaynor8f42fe42013-12-24 13:15:52 -08003OpenSSL Backend
4===============
Donald Stuffte51fb932013-10-27 17:26:17 -04005
Alex Stapletonc368ac22013-12-31 13:43:38 +00006The `OpenSSL`_ C library.
Alex Gaynor6d02e2d2013-09-30 10:37:22 -07007
Alex Gaynorf8796b12013-12-13 20:28:55 -08008.. data:: cryptography.hazmat.backends.openssl.backend
Alex Gaynor6d02e2d2013-09-30 10:37:22 -07009
Paul Kehrer3f17c7c2014-01-20 16:32:26 -060010 This is the exposed API for the OpenSSL backend.
Paul Kehrer2502ce52014-01-18 09:32:47 -060011
Paul Kehrercfa2d622014-01-19 14:01:25 -060012 .. attribute:: name
Paul Kehrer2502ce52014-01-18 09:32:47 -060013
Paul Kehrercfa2d622014-01-19 14:01:25 -060014 The string name of this backend: ``"openssl"``
Alex Gaynor6d02e2d2013-09-30 10:37:22 -070015
Paul Kehrer3f17c7c2014-01-20 16:32:26 -060016 .. method:: register_osrandom_engine()
17
18 Registers the OS random engine as default. This will effectively
19 disable OpenSSL's default CSPRNG.
20
21 .. method:: unregister_osrandom_engine()
22
23 Unregisters the OS random engine if it is default. This will restore
24 the default OpenSSL CSPRNG. If the OS random engine is not the default
25 engine (e.g. if another engine is set as default) nothing will be
26 changed.
27
28OS Random Engine
29----------------
30
31OpenSSL has a CSPRNG that it seeds when starting up. Unfortunately, its state
32is replicated when the process is forked and child processes can deliver
33similar or identical random values. OpenSSL has landed a patch to mitigate this
34issue, but this project can't rely on users having recent versions.
35
36To work around this cryptography uses a custom OpenSSL engine that replaces the
37standard random source with one that fetches entropy from ``/dev/urandom`` (or
38CryptGenRandom on Windows). This engine is **active** by default when importing
39the OpenSSL backend. It is added to the engine list but not activated if you
40only import the binding.
41
Alex Gaynor6d02e2d2013-09-30 10:37:22 -070042.. _`OpenSSL`: https://www.openssl.org/