Fix #826: Suppress cryptography FFDH deprecation warning and add decrepit fallback - #830
sarthak-shubham wants to merge 1 commit into
Conversation
…decrepit fallback
|
@ronf following up from #826 - I went with a try/except ImportError fallback scoped to the single dh symbol here, rather than the _algs/_decrepit_algs registry from cipher.py, since there's only one thing to fall back on here, not a list. Let me know if you'd rather I match the registry pattern for consistency. Also, the CI workflow is waiting on approval to run whenever you get a chance. |
|
Is there a way to do this which avoids having to insert the warnings block in each of the DH class methods? I see that the decrepit module doesn't yet have the asymmetric algorithms in it, so we can't count on that succeeding to avoid the warnings. However, I'd really like to find a way to suppress the warnings once at import time and not have to go through that code every time a DH key is instantiated. |
Fixes #826
Addresses the CryptographyDeprecationWarning raised when using FFDH key exchange with cryptography v50.0.0+.
Changes:
Wraps FFDH operations in warnings.catch_warnings() to suppress CryptographyDeprecationWarning locally, preventing it from leaking into end-user logs.
Adds a try/except ImportError fallback to import dh from cryptography.hazmat.decrepit.asymmetric if it is eventually removed from primitives, following the same pattern used for deprecated symmetric ciphers in crypto/cipher.py.
Tested with python -m unittest tests.test_kex — all 14 tests pass.