Repository navigation
Fix #826: Suppress cryptography FFDH deprecation warning and add decrepit fallback - #830
sarthak-shubham wants to merge 2 commits into
Conversation
…decrepit fallback
|
@ronf following up from #826 - I went with a try/except ImportError fallback scoped to the single dh symbol here, rather than the _algs/_decrepit_algs registry from cipher.py, since there's only one thing to fall back on here, not a list. Let me know if you'd rather I match the registry pattern for consistency. Also, the CI workflow is waiting on approval to run whenever you get a chance. |
|
Is there a way to do this which avoids having to insert the warnings block in each of the DH class methods? I see that the decrepit module doesn't yet have the asymmetric algorithms in it, so we can't count on that succeeding to avoid the warnings. However, I'd really like to find a way to suppress the warnings once at import time and not have to go through that code every time a DH key is instantiated. |
400b24d to
43dd157
Compare
|
@ronf Yes, I understand the per-method overhead issue you pointed towards. I've updated the PR to mirror the pattern you're already using in crypto/cipher.py. Instead of wrapping each method, the classes are now aliased at the module level inside a single warnings.catch_warnings() block. This safely catches the deprecation warning just once during import, which lets us remove the suppression blocks (and their overhead) from the DH class methods. I kept the try/except block exactly as is, so it will still safely fall back to decrepit whenever they eventually migrate it out of primitives. And also tested this against cryptography v50.0.0 and it successfully catches the warning without leaking globally. Let me know if this looks good to you. |
Fixes #826
Addresses the CryptographyDeprecationWarning raised when using FFDH key exchange with cryptography v50.0.0+.
Changes:
Wraps FFDH operations in warnings.catch_warnings() to suppress CryptographyDeprecationWarning locally, preventing it from leaking into end-user logs.
Adds a try/except ImportError fallback to import dh from cryptography.hazmat.decrepit.asymmetric if it is eventually removed from primitives, following the same pattern used for deprecated symmetric ciphers in crypto/cipher.py.
Tested with python -m unittest tests.test_kex — all 14 tests pass.