certs
tit.certs ¶
One verifying :class:ssl.SSLContext for every HTTPS request the toolbox makes.
The SimNIBS container ships a conda-built Python whose OpenSSL still carries the build-time
placeholder CA paths (.../_h_env_placehold_placehold.../ssl/cert.pem), so
:func:ssl.create_default_context there trusts nothing and every urllib call dies with
CERTIFICATE_VERIFY_FAILED. :func:ssl_context fixes that by naming a bundle explicitly:
SSL_CERT_FILE/REQUESTS_CA_BUNDLE-- the escape hatch for a TLS-inspecting proxy;- :mod:
certifi, which the SimNIBS environment already has; - a well-known system bundle (
/etc/ssl/certs/ca-certificates.crtand friends); - the interpreter default, for hosts where it works.
Verification is never disabled -- no CERT_NONE, no check_hostname = False, not behind a
flag. When no bundle can be found the request fails and :func:ca_bundle_hint says what to set.
ca_bundle ¶
ca_bundle() -> str | None
The CA bundle to verify against, or None to fall back to the interpreter default.
Source code in tit/certs.py
ssl_context ¶
ssl_context() -> SSLContext
A verifying context: hostname checking on, CERT_REQUIRED, best bundle available.