-
Notifications
You must be signed in to change notification settings - Fork 422
Add support for querying the negotiated TLS version. #184
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -2129,6 +2129,20 @@ def test_get_cipher_bits(self): | |
self.assertEqual(server_cipher_bits, client_cipher_bits) | ||
|
||
|
||
def test_get_protocol_version(self): | ||
""" | ||
:py:obj:`Connection.get_protocol_version` returns a :py:class:`int` | ||
giving the protocol version of the current connection. | ||
""" | ||
server, client = self._loopback() | ||
server_protocol_version, client_protocol_version = \ | ||
server.get_protocol_version(), client.get_protocol_version() | ||
|
||
self.assertIsInstance(server_protocol_version, int) | ||
self.assertIsInstance(client_protocol_version, int) | ||
|
||
self.assertEqual(server_protocol_version, client_protocol_version) | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This assertion would be satisfied if the implementation accidentally always returned a constant integer ( Perhaps this test could make a stronger assertion about the value? It might even be worth having a couple tests for a couple different values. |
||
|
||
|
||
class ConnectionGetCipherListTests(TestCase): | ||
""" | ||
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It may be hard for most people to generalize from "0x303 means TLS 1.2" to an understanding of other values. Or maybe that's just mean. Anyway, can you expand this documentation or make it easier to understand these values some other way? An example of a non-documentation solution might be to make the result self-documenting by defining a collection of symbolic constants and referring to that collection here. Or another solution might be to refer to some existing OpenSSL documentation about this value.
Which brings me to another point, where is the documentation for
SSL_version
? I can't find any. I did findSSL_get_version
which apparently returns a string instead. Exposing that instead might be another way to solve the documentation issue - since "TLS1.2" doesn't need as much explanation as 0x303 (though just going by the OpenSSL documentation, I don't know if "TLSv1.2" is a value that will ever be returned bySSL_get_version
! It only documents "SSLv2", "SSLv3", and "TLSv1" - oh, and, awesomely, "unknown").