pub struct PyVerificationPolicy { /* private fields */ }Expand description
Optional parameters that control certificate chain verification.
All fields have safe defaults so you only need to set what differs from the standard WebPKI TLS server / client validation.
server_names accepts a list of DNS hostnames or IP address literals.
When more than one name is given, name_match controls whether the
certificate must cover any (default) or all of them:
"any"— connection validation: the certificate is accepted if it matches at least one name in the list (e.g. you are connecting to one of several possible endpoints)."all"— cert assessment: the certificate must cover every name (e.g. checking a cert covers your entire domain set before deploying).
import synta.x509 as x509
# Single name — classic behaviour:
policy = x509.VerificationPolicy(server_names=["example.com"])
# Any-match: accept the cert if it covers either name (connection validation):
policy = x509.VerificationPolicy(
server_names=["example.com", "www.example.com"],
name_match="any",
)
# All-match: verify the cert covers every name (cert assessment):
policy = x509.VerificationPolicy(
server_names=["example.com", "api.example.com"],
name_match="all",
)
# Strict RFC 5280 profile with a fixed validation time, no SAN check:
policy = x509.VerificationPolicy(
profile="rfc5280",
validation_time=1_700_000_000,
max_chain_depth=4,
)Trait Implementations§
impl DerefToPyAny for PyVerificationPolicy
impl ExtractPyClassWithClone for PyVerificationPolicy
Source§impl<'py> IntoPyObject<'py> for PyVerificationPolicy
impl<'py> IntoPyObject<'py> for PyVerificationPolicy
Source§type Target = PyVerificationPolicy
type Target = PyVerificationPolicy
The Python output type
Source§type Output = Bound<'py, <PyVerificationPolicy as IntoPyObject<'py>>::Target>
type Output = Bound<'py, <PyVerificationPolicy as IntoPyObject<'py>>::Target>
The smart pointer type to use. Read more
Source§fn into_pyobject(
self,
py: Python<'py>,
) -> Result<<Self as IntoPyObject<'_>>::Output, <Self as IntoPyObject<'_>>::Error>
fn into_pyobject( self, py: Python<'py>, ) -> Result<<Self as IntoPyObject<'_>>::Output, <Self as IntoPyObject<'_>>::Error>
Performs the conversion.
Source§impl PyClass for PyVerificationPolicy
impl PyClass for PyVerificationPolicy
Source§impl PyClassImpl for PyVerificationPolicy
impl PyClassImpl for PyVerificationPolicy
Source§const IS_BASETYPE: bool = false
const IS_BASETYPE: bool = false
#[pyclass(subclass)]
Source§const IS_SUBCLASS: bool = false
const IS_SUBCLASS: bool = false
#[pyclass(extends=…)]
Source§const IS_MAPPING: bool = false
const IS_MAPPING: bool = false
#[pyclass(mapping)]
Source§const IS_SEQUENCE: bool = false
const IS_SEQUENCE: bool = false
#[pyclass(sequence)]
Source§const IS_IMMUTABLE_TYPE: bool = false
const IS_IMMUTABLE_TYPE: bool = false
#[pyclass(immutable_type)]
Source§const RAW_DOC: &'static CStr = /// Optional parameters that control certificate chain verification.
///
/// All fields have safe defaults so you only need to set what differs from
/// the standard WebPKI TLS server / client validation.
///
/// ``server_names`` accepts a list of DNS hostnames or IP address literals.
/// When more than one name is given, ``name_match`` controls whether the
/// certificate must cover **any** (default) or **all** of them:
///
/// * ``"any"`` — connection validation: the certificate is accepted if it
/// matches at least one name in the list (e.g. you are connecting to one
/// of several possible endpoints).
/// * ``"all"`` — cert assessment: the certificate must cover every name
/// (e.g. checking a cert covers your entire domain set before deploying).
///
/// ```python,ignore
/// import synta.x509 as x509
///
/// # Single name — classic behaviour:
/// policy = x509.VerificationPolicy(server_names=["example.com"])
///
/// # Any-match: accept the cert if it covers either name (connection validation):
/// policy = x509.VerificationPolicy(
/// server_names=["example.com", "www.example.com"],
/// name_match="any",
/// )
///
/// # All-match: verify the cert covers every name (cert assessment):
/// policy = x509.VerificationPolicy(
/// server_names=["example.com", "api.example.com"],
/// name_match="all",
/// )
///
/// # Strict RFC 5280 profile with a fixed validation time, no SAN check:
/// policy = x509.VerificationPolicy(
/// profile="rfc5280",
/// validation_time=1_700_000_000,
/// max_chain_depth=4,
/// )
/// ```
const RAW_DOC: &'static CStr = /// Optional parameters that control certificate chain verification. /// /// All fields have safe defaults so you only need to set what differs from /// the standard WebPKI TLS server / client validation. /// /// ``server_names`` accepts a list of DNS hostnames or IP address literals. /// When more than one name is given, ``name_match`` controls whether the /// certificate must cover **any** (default) or **all** of them: /// /// * ``"any"`` — connection validation: the certificate is accepted if it /// matches at least one name in the list (e.g. you are connecting to one /// of several possible endpoints). /// * ``"all"`` — cert assessment: the certificate must cover every name /// (e.g. checking a cert covers your entire domain set before deploying). /// /// ```python,ignore /// import synta.x509 as x509 /// /// # Single name — classic behaviour: /// policy = x509.VerificationPolicy(server_names=["example.com"]) /// /// # Any-match: accept the cert if it covers either name (connection validation): /// policy = x509.VerificationPolicy( /// server_names=["example.com", "www.example.com"], /// name_match="any", /// ) /// /// # All-match: verify the cert covers every name (cert assessment): /// policy = x509.VerificationPolicy( /// server_names=["example.com", "api.example.com"], /// name_match="all", /// ) /// /// # Strict RFC 5280 profile with a fixed validation time, no SAN check: /// policy = x509.VerificationPolicy( /// profile="rfc5280", /// validation_time=1_700_000_000, /// max_chain_depth=4, /// ) /// ```
Docstring for the class provided on the struct or enum. Read more
Source§const DOC: &'static CStr
const DOC: &'static CStr
Fully rendered class doc, including the
text_signature if a constructor is defined. Read moreSource§type ThreadChecker = SendablePyClass<PyVerificationPolicy>
type ThreadChecker = SendablePyClass<PyVerificationPolicy>
This handles following two situations: Read more
Source§type PyClassMutability = <<PyAny as PyClassBaseType>::PyClassMutability as PyClassMutability>::MutableChild
type PyClassMutability = <<PyAny as PyClassBaseType>::PyClassMutability as PyClassMutability>::MutableChild
Immutable or mutable
Source§type BaseNativeType = PyAny
type BaseNativeType = PyAny
The closest native ancestor. This is
PyAny by default, and when you declare
#[pyclass(extends=PyDict)], it’s PyDict.fn items_iter() -> PyClassItemsIter
fn lazy_type_object() -> &'static LazyTypeObject<Self>
fn dict_offset() -> Option<isize>
fn weaklist_offset() -> Option<isize>
Source§impl PyClassNewTextSignature for PyVerificationPolicy
impl PyClassNewTextSignature for PyVerificationPolicy
const TEXT_SIGNATURE: &'static str = "(*, server_names=None, name_match=None, validation_time=None, max_chain_depth=8, profile=None)"
Source§impl PyMethods<PyVerificationPolicy> for PyClassImplCollector<PyVerificationPolicy>
impl PyMethods<PyVerificationPolicy> for PyClassImplCollector<PyVerificationPolicy>
fn py_methods(self) -> &'static PyClassItems
Source§impl PyTypeInfo for PyVerificationPolicy
impl PyTypeInfo for PyVerificationPolicy
Source§fn type_object_raw(py: Python<'_>) -> *mut PyTypeObject
fn type_object_raw(py: Python<'_>) -> *mut PyTypeObject
Returns the PyTypeObject instance for this type.
Source§fn type_object(py: Python<'_>) -> Bound<'_, PyType>
fn type_object(py: Python<'_>) -> Bound<'_, PyType>
Returns the safe abstraction over the type object.
Auto Trait Implementations§
impl Freeze for PyVerificationPolicy
impl RefUnwindSafe for PyVerificationPolicy
impl Send for PyVerificationPolicy
impl Sync for PyVerificationPolicy
impl Unpin for PyVerificationPolicy
impl UnsafeUnpin for PyVerificationPolicy
impl UnwindSafe for PyVerificationPolicy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<'py, T> IntoPyObjectExt<'py> for Twhere
T: IntoPyObject<'py>,
impl<'py, T> IntoPyObjectExt<'py> for Twhere
T: IntoPyObject<'py>,
Source§fn into_bound_py_any(self, py: Python<'py>) -> Result<Bound<'py, PyAny>, PyErr>
fn into_bound_py_any(self, py: Python<'py>) -> Result<Bound<'py, PyAny>, PyErr>
Converts
self into an owned Python object, dropping type information.Source§impl<T> PyErrArguments for T
impl<T> PyErrArguments for T
Source§impl<T> PyTypeCheck for Twhere
T: PyTypeInfo,
impl<T> PyTypeCheck for Twhere
T: PyTypeInfo,
Source§const NAME: &'static str = T::NAME
const NAME: &'static str = T::NAME
👎Deprecated since 0.27.0:
Use ::classinfo_object() instead and format the type name at runtime. Note that using built-in cast features is often better than manual PyTypeCheck usage.
Name of self. This is used in error messages, for example.