Add a public API to calculate fingerprints of LeafCert instances
まだ誰も着手していません。
評価
調査の方向性
まず既存の LeafCert API と Blob API を調査し、次に証明書の表現を ssl.PEM_cert_to_DER_cert() および aiohttp client_reqrep.py のリファレンスと比較します。公開 fingerprint API を定義し、fingerprint に独自のクラスが必要かどうかを解決します。要求された fingerprint へのアクセスが利用可能で、その動作がクライアント側の計算と一致すれば完了です。
索引モデルが issue の本文から書いたものです。
説明
So I've been finally integrating trustme into aiohttp's test today.
Turns out that certificate fingerprint calculation isn't well-documented on the Internet for Python stdlib's ssl module. All examples use pyOpenSSL instead.
So after fighting it for a while, I've figured out that one should turn certificate into DER format as opposed to PEM (ssl.PEM_cert_to_DER_cert()), because it's what SSLSocket.getpeercert() returns and what client uses to calculate hash: https://github.com/aio-libs/aiohttp/commit/c180800a4c90dc123d05311edbec92a3a82d6317#diff-484462fced51d1a06b1d93b4a44dd535R69
Ref: https://github.com/aio-libs/aiohttp/blob/c9dabcb/aiohttp/client_reqrep.py#L105-L136
So I think it'd be nice to wrap it into a method bound to LeafCert (and maybe Blob?).
The suggested API is:
# fingerprint calc function wrapped with `lru_cache`
LeafCert.make_fingerprint(hash_function='sha256')
# @properties:
LeafCert.sha256_fingerprint
LeafCert.sha1_fingerprint
LeafCert.md5_fingerprint
Maybe fingerprint would need to be represented by its own Fingerprint class, not just some bytes.
- 主要言語
- Python
- スター
- 608
- フォーク
- 34
- 平均マージ
- 2日 20時間
- マージ済み PR(30日)
- 2
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
python-trio/trustme のほかの issue
-
難易度 3/5 1〜2日 初心者へのやさしさ 35/100
python-trio/trustme#723 ·
-
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
python-trio/trustme#40 · コメント 2 件 · リアクション 1 件 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
python-trio/trustme#22 · コメント 3 件 ·
python-trio/trustme の issue をすべて見る
似ている issue
-
namespace operations
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
EclipseFdn/open-vsx.org#14043 ·
メンテナーはふだん 1 日以内に返信
-
feedback simulation workshop
難易度 2/5 1〜3時間 初心者へのやさしさ 73/100
githubnext/gh-aw-workshop#4455 ·
メンテナーはふだん 1 日以内に返信
-
Triage 🩺
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
メンテナーはふだん 1 日以内に返信
-
[BUG] Container scenario crashes without expected_recovery_time, kube DNS example uses retry_waitオープンneeds-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 77/100
krkn-chaos/krkn#1627 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
NousResearch/hermes-agent#136483 ·
メンテナーはふだん 1 日以内に返信