Public API to retrieve cert key and cert chain files written to the fs separately
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 35/100
Direzione di ricerca
Inizia esaminando il comportamento attuale della trustme API descritto nella issue e confrontalo con le integrazioni citate in cheroot, CherryPy, aiohttp e Flask. Definisci API pubbliche che espongano separatamente i file del certificato, della chiave privata e della catena di certificati, quindi aggiungi una copertura che dimostri che ogni percorso restituito è adatto alla corrispondente opzione di configurazione del server.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Usually at high-level web servers expose separate configuration options for a certificate file, a private key file, and a certificate chain file.
Currently trustme forces users to use one file for both certificate file and its key file (as it https://github.com/aio-libs/aiohttp/commit/c180800a4c90dc123d05311edbec92a3a82d6317#diff-3ba621217225120eff2c061666b8043cR284) and use CA cert for chain option.
From the API perspective, it looks confusing to any humble human being who isn't proficient in TLS.
When one looks at such tests they're puzzled: why options named explicitly as key and cert receive the same var? maybe it's a bug? what's going on here?
Same for cert chain: why does it look like instead of some mysterious chain file there's a certificate or the CA?
Proofs:
- https://github.com/cherrypy/cheroot/blob/d31adfe/cheroot/ssl/__init__.py#L24
- https://github.com/cherrypy/cheroot/blob/d31adfe/cheroot/ssl/builtin.py#L91
- https://github.com/cherrypy/cheroot/blob/d31adfe/cheroot/ssl/pyopenssl.py#L241
- https://github.com/cherrypy/cherrypy/blob/e10b984/cherrypy/_cpserver.py#L104-L112
- https://github.com/aio-libs/aiohttp/blob/master/aiohttp/worker.py#L188-L191
- https://github.com/pallets/flask/blob/master/flask/cli.py#L733-L738
I think this use case deserves corresponding public APIs in place. What do you think?
- Lingua principale
- Python
- Stelle
- 608
- Fork
- 34
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di python-trio/trustme
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
python-trio/trustme#723 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
python-trio/trustme#39 · 4 commenti · 1 reazione ·
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
python-trio/trustme#22 · 3 commenti ·
Tutte le issue di python-trio/trustme
Issue simili
-
[Bug] @deck.gl/arcgis dist import resolves to unpublished @deck.gl/core source path (9.3.11, 9.4.0)Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
workflow: a tick's dispatch counts as 'only this step', and no review self-grants a round unattendedApertaworkflow
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
kristofdegrave/homeassistant-smart-charging#1505 ·
I maintainer di solito rispondono entro 1 giorno
-
New Submission: TropWATERApertametadata submission
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
canonical/content-cache-operator#163 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
[submission]Apertasubmission
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 65/100
leanprover/lean-eval-submissions#1852 ·
I maintainer di solito rispondono entro 1 giorno