如何在Python SSL Socket中设置自定义密码套件列表
Solution for Setting Custom Cipher Suite List in Python SSL
Got it, let's sort this out for you. The core thing to remember here is that Python's ssl.SSLContext.set_ciphers() method doesn't accept a list directly — it expects a single string where each cipher suite is separated by colons, which is the native format OpenSSL uses. Since your custom cipher set can't be built with the standard wildcard strings like ALL:!COMPLEMENTOFDEFAULT:!eNULL, converting your list to this colon-separated format is the way to go.
Step-by-Step Code Example
Here's how to implement this properly:
import socket import ssl import pprint # Define your custom cipher suite list custom_cipher_list = [ 'DHE-RSA-AES128-SHA', 'DHE-RSA-AES256-SHA', 'ECDHE-RSA-AES128-GCM-SHA256', # Add any other ciphers you need here ] # Convert the list to a colon-separated string (required by set_ciphers) cipher_config_string = ':'.join(custom_cipher_list) # Create the SSL context and apply the custom ciphers context = ssl.create_default_context() try: context.set_ciphers(cipher_config_string) print("Custom cipher suite successfully applied!") # Optional: Verify the configured ciphers print("\nConfigured cipher suites:") pprint.pprint(context.get_ciphers()) except ssl.SSLError as error: print(f"Failed to set ciphers: {error}") print("Tip: Check if all ciphers in your list are supported by your installed OpenSSL version.")
Key Notes
- Verify Cipher Support: If you hit an error, run
openssl ciphers -vin your terminal to list all cipher suites supported by your OpenSSL installation. This helps you confirm if any of your custom ciphers are outdated or unsupported. - Version Compatibility: Newer cipher suites (like those using GCM or ChaCha20) require up-to-date versions of Python and OpenSSL. Make sure your environment is updated if you need these.
内容的提问来源于stack exchange,提问作者user9371654
相关产品推荐
相关产品推荐

