python / python/cpython

Document OpenSSL version requirements and post-quantum groups for the ssl group and signature algorithm APIs

Open
#154,517 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

3.15 3.16 docs topic-SSL
Dominant language
Python
Stars
77.2k
Forks
35.9k
PR merge metrics
PR metrics pending

Description

Documentation

Python 3.15 added SSLContext.set_groups(), SSLContext.get_groups() and SSLSocket.group() for choosing and inspecting the groups used for TLS key agreement. This is also how you reach the post-quantum hybrid key exchange that OpenSSL 3.5 now offers by default, such as X25519MLKEM768. The same release added ssl.get_sigalgs(), SSLSocket.client_sigalg() and SSLSocket.server_sigalg() for signature algorithms.

The reference documentation for both sets of methods is thinner than it could be.

Five of them need a specific OpenSSL version and raise NotImplementedError when linked against an older one, but the reference docs don't say so:

  • SSLSocket.group() needs OpenSSL 3.2 or later
  • SSLContext.get_groups() needs OpenSSL 3.5 or later
  • ssl.get_sigalgs() needs OpenSSL 3.4 or later
  • SSLSocket.client_sigalg() needs OpenSSL 3.5 or later
  • SSLSocket.server_sigalg() needs OpenSSL 3.5 or later

Each requirement is already stated in the What's New in 3.15 entries and enforced in Modules/_ssl.c, so this is only about the reference pages.

There are a few other gaps around the group API. set_groups() has no example and never mentions that it supports post-quantum groups, even though the What's New in 3.15 does. set_ecdh_curve() doesn't point readers at the newer and more general set_groups(). And the TLS 1.3 section says nothing about key agreement groups or the post-quantum hybrids that are now enabled by default.

Linked PRs
  • gh-154518

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the SSL reference pages for set_groups(), get_groups(), group(), the signature-algorithm APIs, set_ecdh_curve(), and the TLS 1.3 section, then compare their existing details with Modules/_ssl.c and the What's New in 3.15 entries. Done means the documented OpenSSL requirements, NotImplementedError behavior, post-quantum group support, examples, and cross-references cover the gaps described in the issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
documentation
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.