| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: python313-pyOpenSSL | Distribution: openSUSE Tumbleweed |
| Version: 26.3.0 | Vendor: openSUSE |
| Release: 1.2 | Build date: Sun Jun 14 11:18:38 2026 |
| Group: Unspecified | Build host: reproducible |
| Size: 719407 | Source RPM: python-pyOpenSSL-26.3.0-1.2.src.rpm |
| Packager: https://bugs.opensuse.org | |
| Url: https://github.com/pyca/pyopenssl | |
| Summary: Python wrapper module around the OpenSSL library | |
pyOpenSSL is a set of Python bindings for OpenSSL. It includes some low-level cryptography APIs but is primarily focused on providing an API for using the TLS protocol from Python. pyOpenSSL is now a pure-Python project with a dependency on a new project, cryptography (<https://github.com/pyca/cryptography>), which provides (among other things) a cffi-based interface to OpenSSL.
Apache-2.0
* Sun Jun 14 2026 Dirk Müller <dmueller@suse.com>
- update to 26.3.0:
* Dropped support for Python 3.8.
* The minimum cryptography version is now 49.0.0.
* Removed deprecated OpenSSL.crypto.X509Req,
OpenSSL.crypto.dump_certificate_request, and
OpenSSL.crypto.load_certificate_request. cryptography.x509
should be used instead.
* OpenSSL.SSL.Connection.set_session now raises ValueError if
the Session was obtained from a Connection that was using a
different Context than this one. OpenSSL requires (but does
not verify) that sessions only be re-used with a compatible
SSL_CTX, so this contract is now enforced.
* Deprecated OpenSSL.crypto.PKey.generate_key and
OpenSSL.crypto.PKey.check. The key generation and loading
APIs in cryptography should be used instead.
* Deprecated OpenSSL.crypto.dump_privatekey. The serialization
APIs on cryptography private key types should be used
instead.
* Deprecated all the mutable APIs on OpenSSL.crypto.X509:
set_version, set_pubkey, sign, set_serial_number,
gmtime_adj_notAfter, gmtime_adj_notBefore, set_notBefore,
set_notAfter, set_issuer, and set_subject.
cryptography.x509.CertificateBuilder should be used instead.
* Deprecated OpenSSL.SSL.Context.set_passwd_cb. Users should
decrypt and load their private keys themselves, with
cryptography's key loading APIs, and then call
OpenSSL.SSL.Context.use_privatekey.
* Deprecated OpenSSL.crypto.X509Name, as well as the remaining
APIs that consume or return it:
OpenSSL.crypto.X509.get_issuer,
OpenSSL.crypto.X509.get_subject, and
OpenSSL.SSL.Context.set_client_ca_list. The APIs in
cryptography.x509 should be used instead.
* OpenSSL.SSL.Connection.get_client_ca_list now takes an
as_cryptography keyword-argument. When True is passed then
cryptography.x509.Name are returned, instead of
OpenSSL.crypto.X509Name. In the future, passing False (the
default) will be deprecated.
* Sun May 10 2026 Gemini CLI <gemini-cli@suse.com>
- update to 26.2.0:
* Maximum supported cryptography version is now 48.x.
* Added OpenSSL.SSL.Connection.set_options to set options on a
per-connection basis.
* Removed deprecated OpenSSL.crypto.X509Extension,
OpenSSL.crypto.X509Req.add_extension,
OpenSSL.crypto.X509Req.get_extensions,
OpenSSL.crypto.X509.add_extension,
OpenSSL.crypto.X509.get_extensions.
* It is now an error to calling any mutating method on
OpenSSL.SSL.Context after it has been used to create a
Connection.
- refresh skip-networked-test.patch
* Sun Apr 26 2026 Dirk Müller <dmueller@suse.com>
- update to 26.1.0 (CVE-2026-40475, bsc#1262803):
* Maximum supported cryptography version is now 47.x.
* Fixed X509Name field setters to correctly pass the value
length to OpenSSL. Previously, values containing NUL bytes
would be silently truncated, causing a divergence between the
stored ASN.1 value and the value visible from Python. Credit
to BudongJW for reporting the issue. CVE-2026-40475
* Wed Mar 18 2026 Daniel Garcia <daniel.garcia@suse.com>
- update to 26.0.0 (bsc#1259808, CVE-2026-27459, bsc#1259804, CVE-2026-27448):
[#]# Backward-incompatible changes:
* Dropped support for Python 3.7.
* The minimum cryptography version is now 46.0.0.
[#]# Changes:
- Added support for using aws-lc instead of OpenSSL.
- Properly raise an error if a DTLS cookie callback returned a
cookie longer than DTLS1_COOKIE_LENGTH bytes. Previously this
would result in a buffer-overflow. Credit to dark_haxor for
reporting the issue. CVE-2026-27459
- Added OpenSSL.SSL.Connection.get_group_name to determine which
group name was negotiated.
- Context.set_tlsext_servername_callback now handles exceptions
raised in the callback by calling sys.excepthook and returning a
fatal TLS alert. Previously, exceptions were silently swallowed
and the handshake would proceed as if the callback had succeeded.
Credit to Leury Castillo for reporting this issue. CVE-2026-27448
* Wed Oct 08 2025 Markéta Machová <mmachova@suse.com>
- Skip test_client_receives_servers_data failing with openssl 3.6.0
and rewrite tests exclusion to be more atomic
* Mon Sep 29 2025 Dirk Müller <dmueller@suse.com>
- update to 25.3.0:
* Maximum supported cryptography version is now 46.x.
* The minimum cryptography version is now 45.0.7.
* pyOpenSSL now sets SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER on
connections by default, matching CPython's behavior.
* Added OpenSSL.SSL.Context.clear_mode.
* Added OpenSSL.SSL.Context.set_tls13_ciphersuites to set the
allowed TLS 1.3 ciphers.
* Added OpenSSL.SSL.Connection.set_info_callback
* Sat Jul 12 2025 Dirk Müller <dmueller@suse.com>
- update to 25.1.0:
* Attempting using any methods that mutate an
OpenSSL.SSL.Context after it has been used to create an
OpenSSL.SSL.Connection will emit a warning. In a future
release, this will raise an exception.
* cryptography maximum version has been increased to 45.0.x.
* Thu Apr 17 2025 Marcus Rueckert <mrueckert@suse.de>
- dont use suse version for the dist info handling as people can
build with newer setuptools on older distros
* Tue Apr 01 2025 Markéta Machová <mmachova@suse.com>
- Wrap the metadata directory name in a distro-based conditional
* Wed Mar 26 2025 Steve Kowalik <steven.kowalik@suse.com>
- Normalize metadata directory name.
* Thu Jan 30 2025 Steve Kowalik <steven.kowalik@suse.com>
- Switch to pyproject macros.
- Add typing-extensions to Requires for 3.11 and 3.12.
* Wed Jan 29 2025 ecsos <ecsos@opensuse.org>
- Update to 25.0.0
* Backward-incompatible changes: -
* Deprecations: -
* Changes:
- Corrected type annotations on Context.set_alpn_select_callback,
Context.set_session_cache_mode, Context.set_options, Context.set_mode,
X509.subject_name_hash, and X509Store.load_locations.
- Deprecated APIs are now marked using warnings.deprecated. mypy will emit deprecation notices
for them when used with --enable-error-code deprecated.
- Changes from 24.3.0
* Backward-incompatible changes:
- Removed the deprecated OpenSSL.crypto.CRL, OpenSSL.crypto.Revoked, OpenSSL.crypto.dump_crl,
and OpenSSL.crypto.load_crl. cryptography.x509's CRL functionality should be used instead.
- Removed the deprecated OpenSSL.crypto.sign and OpenSSL.crypto.verify.
cryptography.hazmat.primitives.asymmetric's signature APIs should be used instead.
* Deprecations:
- Deprecated OpenSSL.rand - callers should use os.urandom() instead.
- Deprecated add_extensions and get_extensions on OpenSSL.crypto.X509Req and OpenSSL.crypto.X509.
These should have been deprecated at the same time X509Extension was. Users should use pyca/cryptography's X.509 APIs instead.
- Deprecated OpenSSL.crypto.get_elliptic_curves and OpenSSL.crypto.get_elliptic_curve,
as well as passing the reult of them to OpenSSL.SSL.Context.set_tmp_ecdh,
users should instead pass curves from cryptography.
- Deprecated passing X509 objects to OpenSSL.SSL.Context.use_certificate, OpenSSL.SSL.Connection.use_certificate,
OpenSSL.SSL.Context.add_extra_chain_cert, and OpenSSL.SSL.Context.add_client_ca, users should instead
pass cryptography.x509.Certificate instances. This is in preparation for deprecating pyOpenSSL's X509 entirely.
- Deprecated passing PKey objects to OpenSSL.SSL.Context.use_privatekey and OpenSSL.SSL.Connection.use_privatekey,
users should instead pass cryptography priate key instances. This is in preparation for deprecating pyOpenSSL's PKey entirely.
* Changes:
- cryptography maximum version has been increased to 44.0.x.
- OpenSSL.SSL.Connection.get_certificate, OpenSSL.SSL.Connection.get_peer_certificate,
OpenSSL.SSL.Connection.get_peer_cert_chain, and OpenSSL.SSL.Connection.get_verified_chain
now take an as_cryptography keyword-argument. When True is passed then
cryptography.x509.Certificate are returned, instead of OpenSSL.crypto.X509.
In the future, passing False (the default) will be deprecated.
- Rebase skip-networked-test.patch.
* Mon Jan 13 2025 Dominique Leuenberger <dimstar@opensuse.org>
- Do not build tests noarch: they refer to %__isa, which differs
per architecture, invalidating the noarch option.
Fixes build with rpm 4.20.
* Tue Jul 23 2024 Adrian Schröter <adrian@suse.de>
- 24.2.1:
* Deprecated OpenSSL.crypto.X509Req,
OpenSSL.crypto.load_certificate_request,
OpenSSL.crypto.dump_certificate_request.
Instead, cryptography.x509.CertificateSigningRequest,s
cryptography.x509.CertificateSigningRequestBuilder,s
cryptography.x509.load_der_x509_csr,s
or cryptography.x509.load_pem_x509_csr should be used.
* Added type hints for the SSL module. #1308.
* Changed OpenSSL.crypto.PKey.from_cryptography_key to accept public and private EC, ED25519, ED448 keys
* Sat Mar 16 2024 Dirk Müller <dmueller@suse.com>
- update to 24.1.0:
* Removed the deprecated OpenSSL.crypto.PKCS12 and
OpenSSL.crypto.NetscapeSPKI. OpenSSL.crypto.PKCS12 may be
replaced by the PKCS#12 APIs in the cryptography package.
* Mon Jan 29 2024 Dirk Müller <dmueller@suse.com>
- update to 24.0.0:
* Added OpenSSL.SSL.Connection.get_selected_srtp_profile to
determine which SRTP profile was negotiated. #1279.
* Mon Nov 27 2023 Dirk Müller <dmueller@suse.com>
- update to 23.3.0:
* Dropped support for Python 3.6.
* The minimum ``cryptography`` version is now 41.0.5.
* Removed ``OpenSSL.crypto.loads_pkcs7`` and
``OpenSSL.crypto.loads_pkcs12`` which had been deprecated for
3 years.
* Added ``OpenSSL.SSL.OP_LEGACY_SERVER_CONNECT`` to allow
legacy insecure renegotiation between OpenSSL and unpatched
servers.
* Deprecated ``OpenSSL.crypto.PKCS12`` (which was intended to
have been deprecated at the same time as
``OpenSSL.crypto.load_pkcs12``).
* Deprecated ``OpenSSL.crypto.NetscapeSPKI``.
* Deprecated ``OpenSSL.crypto.CRL``
* Deprecated ``OpenSSL.crypto.Revoked``
* Deprecated ``OpenSSL.crypto.load_crl`` and
``OpenSSL.crypto.dump_crl``
* Deprecated ``OpenSSL.crypto.sign`` and
``OpenSSL.crypto.verify``
* Deprecated ``OpenSSL.crypto.X509Extension``
* Changed ``OpenSSL.crypto.X509Store.add_crl`` to also accept
* ``cryptography``'s ``x509.CertificateRevocationList``
arguments in addition
* to the now deprecated ``OpenSSL.crypto.CRL`` arguments.
* Fixed ``test_set_default_verify_paths`` test so that it is
skipped if no network connection is available.
* Mon Jun 19 2023 Dirk Müller <dmueller@suse.com>
- update to 23.2.0:
* Removed ``X509StoreFlags.NOTIFY_POLICY``.
* ``cryptography`` maximum version has been increased to
41.0.x.
* Invalid versions are now rejected in
``OpenSSL.crypto.X509Req.set_version``.
* Added ``X509VerificationCodes`` to ``OpenSSL.SSL``.
* Fri Apr 21 2023 Dirk Müller <dmueller@suse.com>
- add sle15_python_module_pythons (jsc#PED-68)
* Thu Apr 13 2023 Matej Cepl <mcepl@suse.com>
- Make calling of %{sle15modernpython} optional.
* Tue Mar 28 2023 Dirk Müller <dmueller@suse.com>
- update to 23.1.1:
* Worked around an issue in OpenSSL 3.1.0 which caused
`X509Extension.get_short_name` to raise an exception when no
short name was known to OpenSSL.
* Mon Mar 27 2023 Dirk Müller <dmueller@suse.com>
- update to 23.1.0:
* ``cryptography`` maximum version has been increased to
40.0.x.
* Add ``OpenSSL.SSL.Connection.DTLSv1_get_timeout`` and
``OpenSSL.SSL.Connection.DTLSv1_handle_timeout``
to support DTLS timeouts `#1180
* Mon Jan 02 2023 Dirk Müller <dmueller@suse.com>
- update to 23.0.0:
* Add ``OpenSSL.SSL.X509StoreFlags.PARTIAL_CHAIN`` constant to allow for
users
to perform certificate verification on partial certificate chains.
* ``cryptography`` maximum version has been increased to 39.0.x.
- drop pyOpenSSL-pr1158-conditional-__all__.patch (upstream)
/usr/lib/python3.13/site-packages/OpenSSL /usr/lib/python3.13/site-packages/OpenSSL/SSL.py /usr/lib/python3.13/site-packages/OpenSSL/__init__.py /usr/lib/python3.13/site-packages/OpenSSL/__pycache__ /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/SSL.cpython-313.opt-1.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/SSL.cpython-313.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/__init__.cpython-313.opt-1.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/__init__.cpython-313.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/_util.cpython-313.opt-1.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/_util.cpython-313.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/crypto.cpython-313.opt-1.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/crypto.cpython-313.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/debug.cpython-313.opt-1.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/debug.cpython-313.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/rand.cpython-313.opt-1.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/rand.cpython-313.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/version.cpython-313.opt-1.pyc /usr/lib/python3.13/site-packages/OpenSSL/__pycache__/version.cpython-313.pyc /usr/lib/python3.13/site-packages/OpenSSL/_util.py /usr/lib/python3.13/site-packages/OpenSSL/crypto.py /usr/lib/python3.13/site-packages/OpenSSL/debug.py /usr/lib/python3.13/site-packages/OpenSSL/py.typed /usr/lib/python3.13/site-packages/OpenSSL/rand.py /usr/lib/python3.13/site-packages/OpenSSL/version.py /usr/lib/python3.13/site-packages/pyopenssl-26.3.0.dist-info /usr/lib/python3.13/site-packages/pyopenssl-26.3.0.dist-info/INSTALLER /usr/lib/python3.13/site-packages/pyopenssl-26.3.0.dist-info/METADATA /usr/lib/python3.13/site-packages/pyopenssl-26.3.0.dist-info/RECORD /usr/lib/python3.13/site-packages/pyopenssl-26.3.0.dist-info/REQUESTED /usr/lib/python3.13/site-packages/pyopenssl-26.3.0.dist-info/WHEEL /usr/lib/python3.13/site-packages/pyopenssl-26.3.0.dist-info/licenses /usr/lib/python3.13/site-packages/pyopenssl-26.3.0.dist-info/licenses/LICENSE /usr/lib/python3.13/site-packages/pyopenssl-26.3.0.dist-info/top_level.txt /usr/share/doc/packages/python313-pyOpenSSL /usr/share/doc/packages/python313-pyOpenSSL/CHANGELOG.rst /usr/share/doc/packages/python313-pyOpenSSL/README.rst /usr/share/licenses/python313-pyOpenSSL /usr/share/licenses/python313-pyOpenSSL/LICENSE
Generated by rpm2html 1.8.1
Fabrice Bellet, Sun Aug 2 01:28:36 2026