Skip to content

Fix #826: Suppress cryptography FFDH deprecation warning and add decrepit fallback - #830

Open
sarthak-shubham wants to merge 1 commit into
ronf:developfrom
sarthak-shubham:fix-dh-deprecation-warning
Open

sarthak-shubham wants to merge 1 commit into
ronf:developfrom
sarthak-shubham:fix-dh-deprecation-warning

Conversation

@sarthak-shubham

Copy link
Copy Markdown

Fixes #826

Addresses the CryptographyDeprecationWarning raised when using FFDH key exchange with cryptography v50.0.0+.

Changes:

Wraps FFDH operations in warnings.catch_warnings() to suppress CryptographyDeprecationWarning locally, preventing it from leaking into end-user logs.
Adds a try/except ImportError fallback to import dh from cryptography.hazmat.decrepit.asymmetric if it is eventually removed from primitives, following the same pattern used for deprecated symmetric ciphers in crypto/cipher.py.
Tested with python -m unittest tests.test_kex — all 14 tests pass.

@sarthak-shubham

Copy link
Copy Markdown
Author

@ronf following up from #826 - I went with a try/except ImportError fallback scoped to the single dh symbol here, rather than the _algs/_decrepit_algs registry from cipher.py, since there's only one thing to fall back on here, not a list. Let me know if you'd rather I match the registry pattern for consistency.

Also, the CI workflow is waiting on approval to run whenever you get a chance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deprecation warning with Cryptography v50.0.0

1 participant