Fix #826: Suppress cryptography FFDH deprecation warning and add decrepit fallback - #830
Open
sarthak-shubham wants to merge 1 commit into
Open
sarthak-shubham wants to merge 1 commit into
sarthak-shubham wants to merge 1 commit into
Conversation
…decrepit fallback
Author
|
@ronf following up from #826 - I went with a try/except ImportError fallback scoped to the single dh symbol here, rather than the _algs/_decrepit_algs registry from cipher.py, since there's only one thing to fall back on here, not a list. Let me know if you'd rather I match the registry pattern for consistency. Also, the CI workflow is waiting on approval to run whenever you get a chance. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #826
Addresses the CryptographyDeprecationWarning raised when using FFDH key exchange with cryptography v50.0.0+.
Changes:
Wraps FFDH operations in warnings.catch_warnings() to suppress CryptographyDeprecationWarning locally, preventing it from leaking into end-user logs.
Adds a try/except ImportError fallback to import dh from cryptography.hazmat.decrepit.asymmetric if it is eventually removed from primitives, following the same pattern used for deprecated symmetric ciphers in crypto/cipher.py.
Tested with python -m unittest tests.test_kex — all 14 tests pass.