Skip to main content

PyVerificationPolicy

Struct PyVerificationPolicy 

Source
pub struct PyVerificationPolicy { /* private fields */ }
Expand description

Optional parameters that control certificate chain verification.

All fields have safe defaults so you only need to set what differs from the standard WebPKI TLS server / client validation.

server_names accepts a list of DNS hostnames or IP address literals. When more than one name is given, name_match controls whether the certificate must cover any (default) or all of them:

  • "any" — connection validation: the certificate is accepted if it matches at least one name in the list (e.g. you are connecting to one of several possible endpoints).
  • "all" — cert assessment: the certificate must cover every name (e.g. checking a cert covers your entire domain set before deploying).
import synta.x509 as x509

# Single name — classic behaviour:
policy = x509.VerificationPolicy(server_names=["example.com"])

# Any-match: accept the cert if it covers either name (connection validation):
policy = x509.VerificationPolicy(
    server_names=["example.com", "www.example.com"],
    name_match="any",
)

# All-match: verify the cert covers every name (cert assessment):
policy = x509.VerificationPolicy(
    server_names=["example.com", "api.example.com"],
    name_match="all",
)

# Strict RFC 5280 profile with a fixed validation time, no SAN check:
policy = x509.VerificationPolicy(
    profile="rfc5280",
    validation_time=1_700_000_000,
    max_chain_depth=4,
)

Trait Implementations§

Source§

impl<'py> IntoPyObject<'py> for PyVerificationPolicy

Source§

type Target = PyVerificationPolicy

The Python output type
Source§

type Output = Bound<'py, <PyVerificationPolicy as IntoPyObject<'py>>::Target>

The smart pointer type to use. Read more
Source§

type Error = PyErr

The type returned in the event of a conversion error.
Source§

fn into_pyobject( self, py: Python<'py>, ) -> Result<<Self as IntoPyObject<'_>>::Output, <Self as IntoPyObject<'_>>::Error>

Performs the conversion.
Source§

impl PyClass for PyVerificationPolicy

Source§

type Frozen = False

Whether the pyclass is frozen. Read more
Source§

impl PyClassImpl for PyVerificationPolicy

Source§

const IS_BASETYPE: bool = false

#[pyclass(subclass)]
Source§

const IS_SUBCLASS: bool = false

#[pyclass(extends=…)]
Source§

const IS_MAPPING: bool = false

#[pyclass(mapping)]
Source§

const IS_SEQUENCE: bool = false

#[pyclass(sequence)]
Source§

const IS_IMMUTABLE_TYPE: bool = false

#[pyclass(immutable_type)]
Source§

const RAW_DOC: &'static CStr = /// Optional parameters that control certificate chain verification. /// /// All fields have safe defaults so you only need to set what differs from /// the standard WebPKI TLS server / client validation. /// /// ``server_names`` accepts a list of DNS hostnames or IP address literals. /// When more than one name is given, ``name_match`` controls whether the /// certificate must cover **any** (default) or **all** of them: /// /// * ``"any"`` — connection validation: the certificate is accepted if it /// matches at least one name in the list (e.g. you are connecting to one /// of several possible endpoints). /// * ``"all"`` — cert assessment: the certificate must cover every name /// (e.g. checking a cert covers your entire domain set before deploying). /// /// ```python,ignore /// import synta.x509 as x509 /// /// # Single name — classic behaviour: /// policy = x509.VerificationPolicy(server_names=["example.com"]) /// /// # Any-match: accept the cert if it covers either name (connection validation): /// policy = x509.VerificationPolicy( /// server_names=["example.com", "www.example.com"], /// name_match="any", /// ) /// /// # All-match: verify the cert covers every name (cert assessment): /// policy = x509.VerificationPolicy( /// server_names=["example.com", "api.example.com"], /// name_match="all", /// ) /// /// # Strict RFC 5280 profile with a fixed validation time, no SAN check: /// policy = x509.VerificationPolicy( /// profile="rfc5280", /// validation_time=1_700_000_000, /// max_chain_depth=4, /// ) /// ```

Docstring for the class provided on the struct or enum. Read more
Source§

const DOC: &'static CStr

Fully rendered class doc, including the text_signature if a constructor is defined. Read more
Source§

type BaseType = PyAny

Base class
Source§

type ThreadChecker = SendablePyClass<PyVerificationPolicy>

This handles following two situations: Read more
Source§

type PyClassMutability = <<PyAny as PyClassBaseType>::PyClassMutability as PyClassMutability>::MutableChild

Immutable or mutable
Source§

type Dict = PyClassDummySlot

Specify this class has #[pyclass(dict)] or not.
Source§

type WeakRef = PyClassDummySlot

Specify this class has #[pyclass(weakref)] or not.
Source§

type BaseNativeType = PyAny

The closest native ancestor. This is PyAny by default, and when you declare #[pyclass(extends=PyDict)], it’s PyDict.
Source§

fn items_iter() -> PyClassItemsIter

Source§

fn lazy_type_object() -> &'static LazyTypeObject<Self>

Source§

fn dict_offset() -> Option<isize>

Source§

fn weaklist_offset() -> Option<isize>

Source§

impl PyClassNewTextSignature for PyVerificationPolicy

Source§

const TEXT_SIGNATURE: &'static str = "(*, server_names=None, name_match=None, validation_time=None, max_chain_depth=8, profile=None)"

Source§

impl PyMethods<PyVerificationPolicy> for PyClassImplCollector<PyVerificationPolicy>

Source§

fn py_methods(self) -> &'static PyClassItems

Source§

impl PyTypeInfo for PyVerificationPolicy

Source§

const NAME: &'static str = "VerificationPolicy"

Class name.
Source§

const MODULE: Option<&'static str> = ::core::option::Option::None

Module name, if any.
Source§

fn type_object_raw(py: Python<'_>) -> *mut PyTypeObject

Returns the PyTypeObject instance for this type.
Source§

fn type_object(py: Python<'_>) -> Bound<'_, PyType>

Returns the safe abstraction over the type object.
Source§

fn is_type_of(object: &Bound<'_, PyAny>) -> bool

Checks if object is an instance of this type or a subclass of this type.
Source§

fn is_exact_type_of(object: &Bound<'_, PyAny>) -> bool

Checks if object is an instance of this type.
Source§

impl DerefToPyAny for PyVerificationPolicy

Source§

impl ExtractPyClassWithClone for PyVerificationPolicy

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<'py, T> IntoPyObjectExt<'py> for T
where T: IntoPyObject<'py>,

Source§

fn into_bound_py_any(self, py: Python<'py>) -> Result<Bound<'py, PyAny>, PyErr>

Converts self into an owned Python object, dropping type information.
Source§

fn into_py_any(self, py: Python<'py>) -> Result<Py<PyAny>, PyErr>

Converts self into an owned Python object, dropping type information and unbinding it from the 'py lifetime.
Source§

fn into_pyobject_or_pyerr(self, py: Python<'py>) -> Result<Self::Output, PyErr>

Converts self into a Python object. Read more
Source§

impl<T> PyErrArguments for T
where T: for<'py> IntoPyObject<'py> + Send + Sync,

Source§

fn arguments(self, py: Python<'_>) -> Py<PyAny>

Arguments for exception
Source§

impl<T> PyTypeCheck for T
where T: PyTypeInfo,

Source§

const NAME: &'static str = T::NAME

👎Deprecated since 0.27.0:

Use ::classinfo_object() instead and format the type name at runtime. Note that using built-in cast features is often better than manual PyTypeCheck usage.

Name of self. This is used in error messages, for example.
Source§

fn type_check(object: &Bound<'_, PyAny>) -> bool

Checks if object is an instance of Self, which may include a subtype. Read more
Source§

fn classinfo_object(py: Python<'_>) -> Bound<'_, PyAny>

Returns the expected type as a possible argument for the isinstance and issubclass function. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> Ungil for T
where T: Send,