Skip to content

ssl and hashlib: Remove functions deprecated in Python 3.10 #94199

Description

@vstinner

The commit 2875c60 deprecated many ssl and hashlib functions in Python 3.10:

  • ssl.OP_NO_SSLv2
  • ssl.OP_NO_SSLv3
  • ssl.OP_NO_TLSv1
  • ssl.OP_NO_TLSv1_1
  • ssl.OP_NO_TLSv1_2
  • ssl.OP_NO_TLSv1_3
  • ssl.PROTOCOL_SSLv2
  • ssl.PROTOCOL_SSLv3
  • ssl.PROTOCOL_SSLv23 (alias for PROTOCOL_TLS)
  • ssl.PROTOCOL_TLS
  • ssl.PROTOCOL_TLSv1
  • ssl.PROTOCOL_TLSv1_1
  • ssl.PROTOCOL_TLSv1_2
  • ssl.TLSVersion.SSLv3
  • ssl.TLSVersion.TLSv1
  • ssl.TLSVersion.TLSv1_1
  • ssl.wrap_socket()
  • ssl.RAND_pseudo_bytes()
  • ssl.RAND_egd() (already removed since it's not supported by OpenSSL 1.1.1)
  • ssl.SSLContext() without a protocol argument
  • ssl.match_hostname()
  • hashlib.pbkdf2_hmac() (pure Python implementation, fast OpenSSL function will stay)

They emit a DeprecationWarning in Python 3.10 and 3.11. According to PEP 387, they can now be removed in Python 3.12.

I'm not sure that we should actively remove all of these deprecated features, it should be decided on a case by case basis. Backward compatibility is even more complex when it's about security and old security protocols like SSL and old TLS versions.

Activity

  1. added a commit that references this issue on Jun 24, 2022
  2. vstinner commented on Jun 24, 2022

    @vstinner
    MemberAuthor

    What's New in Python 3.10 lists many deprecated ssl functions and announces: "will be removed in 3.11" (Python 3.11).

    But in the meanwhile, PEP 387 was updated to require a feature to be deprecated for 2 Python releases (Python 3.10 and 3.11), not only a single Python release. Some functions were deprecated way before Python 3.10 (emit a DeprecationWarning).

  3. added a commit that references this issue on Jun 25, 2022
  4. added a commit that references this issue on Jun 28, 2022
  5. added a commit that references this issue on Jun 30, 2022
  6. tiran commented on Jul 8, 2022

    @tiran
    Member

    I have created ticket #94598 to track removal of SSL 3.0, TLS 1.0, and TLS 1.1 related features.

  7. vstinner commented on Jul 8, 2022

    @vstinner
    MemberAuthor

    I have created ticket #94598 to track removal of SSL 3.0, TLS 1.0, and TLS 1.1 related features.

    Thank you for that!

  8. added a commit that references this issue on Jul 8, 2022
  9. illia-v commented on Nov 2, 2022

    @illia-v
    Contributor

    Please note that ssl.wrap_socket is still documented on https://docs.python.org/3.12/library/ssl.html#ssl.wrap_socket despite it was removed.

  10. vstinner commented on Nov 2, 2022

    @vstinner
    MemberAuthor

    Please note that ssl.wrap_socket is still documented on https://docs.python.org/3.12/library/ssl.html#ssl.wrap_socket despite it was removed.

    Oops, right. I propose PR #99023 to update the doc.

  11. added a commit that references this issue on Nov 3, 2022
  12. vstinner commented on Nov 3, 2022

    @vstinner
    MemberAuthor

    I merged the last PR to remove keyfile, certfile and check_hostname parameters: ef0e72b

    I close the issue. I removed enough ssl deprecated functions for a single version and @tiran created #94598 to track removal of SSL 3.0, TLS 1.0, and TLS 1.1 related features.

  13. Amer7G7 commented on Dec 29, 2023

    @Amer7G7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    type-bugAn unexpected behavior, bug, or error

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions