Ubuntu22下Python2与Python3调用OpenSSL3中MD4的差异问题
解决Ubuntu22下Python2无法通过hashlib调用MD4的问题
核心原因
Python2的hashlib模块与OpenSSL 3.0的兼容逻辑和Python3不同——Python3的后续版本针对OpenSSL 3.0禁用弱算法的机制做了适配,但Python2的hashlib没有对应的处理,即使系统OpenSSL配置已调整,也无法自动识别启用MD4。
可行解决方案
方案1:临时指定OpenSSL配置(无全局风险)
- 创建一个自定义OpenSSL配置文件(比如
~/openssl-md4.conf),内容如下:
openssl_conf = default_conf [default_conf] ssl_conf = ssl_sect [ssl_sect] system_default = system_default_sect [system_default_sect] CipherString = DEFAULT@SECLEVEL=0
- 运行Python2时通过环境变量加载该配置:
OPENSSL_CONF=~/openssl-md4.conf python2
此时在Python2环境中执行hashlib.new('md4', b"text")即可正常工作。
方案2:全局调整OpenSSL配置(有安全风险,不推荐生产环境)
编辑/etc/ssl/openssl.cnf,添加/修改以下内容:
openssl_conf = default_conf [default_conf] ssl_conf = ssl_sect [ssl_sect] system_default = system_default_sect [system_default_sect] CipherString = DEFAULT@SECLEVEL=0
保存后,所有依赖OpenSSL的进程都会启用弱算法,包括Python2。注意:此操作会降低系统整体SSL安全性,仅适合测试或非敏感环境。
方案3:使用第三方哈希库(最安全推荐)
用pycryptodome替代系统hashlib,它不受系统OpenSSL配置限制:
- 安装适配Python2的版本:
pip2 install pycryptodome
- 在代码中调用MD4:
from Crypto.Hash import MD4 hash_obj = MD4.new(b"text") print(hash_obj.hexdigest())
内容的提问来源于stack exchange,提问作者nathan
相关产品推荐
相关产品推荐

