diff options
| author | Chayim I. Kirshen <c@kirshen.com> | 2021-12-09 14:40:09 +0200 |
|---|---|---|
| committer | Chayim I. Kirshen <c@kirshen.com> | 2021-12-09 14:40:09 +0200 |
| commit | 72addeca0933a23bffa49637a90ffadf26c4eb0e (patch) | |
| tree | 228b76f77d2821c349e49f8ac95a9e98d97ebcf8 | |
| parent | 12c17bfc436ea6784bbc8b2d327d981520858eb7 (diff) | |
| download | redis-py-72addeca0933a23bffa49637a90ffadf26c4eb0e.tar.gz | |
ssl password support
| -rwxr-xr-x | redis/client.py | 2 | ||||
| -rwxr-xr-x | redis/connection.py | 32 |
2 files changed, 31 insertions, 3 deletions
diff --git a/redis/client.py b/redis/client.py index c02bc3a..db3f036 100755 --- a/redis/client.py +++ b/redis/client.py @@ -874,6 +874,7 @@ class Redis(RedisModuleCommands, CoreCommands, SentinelCommands): ssl_cert_reqs="required", ssl_ca_certs=None, ssl_check_hostname=False, + ssl_password=None, max_connections=None, single_connection_client=False, health_check_interval=0, @@ -947,6 +948,7 @@ class Redis(RedisModuleCommands, CoreCommands, SentinelCommands): "ssl_cert_reqs": ssl_cert_reqs, "ssl_ca_certs": ssl_ca_certs, "ssl_check_hostname": ssl_check_hostname, + "ssl_password": ssl_password, } ) connection_pool = ConnectionPool(**kwargs) diff --git a/redis/connection.py b/redis/connection.py index 2001c64..051dc85 100755 --- a/redis/connection.py +++ b/redis/connection.py @@ -879,6 +879,11 @@ class Connection: class SSLConnection(Connection): + """Manages SSL connections to and from the Redis server(s). + This class extends the Connection class, adding SSL functionality, and making + use of ssl.SSLContext (https://docs.python.org/3/library/ssl.html#ssl.SSLContext) + """ # noqa + def __init__( self, ssl_keyfile=None, @@ -886,8 +891,24 @@ class SSLConnection(Connection): ssl_cert_reqs="required", ssl_ca_certs=None, ssl_check_hostname=False, + ssl_ca_path=None, + ssl_password=None, **kwargs, ): + """Constructor + + Args: + ssl_keyfile: Path to an ssl private key. Defaults to None. + ssl_certfile: Path to an ssl certificate. Defaults to None. + ssl_cert_reqs: The string value for the SSLContext.verify_mode (none, optional, required). Defaults to "required". + ssl_ca_certs: The path to a file of concatenated CA certificates in PEM format. Defaults to None. + ssl_check_hostname: If set, match the hostname during the SSL handshake. Defaults to False. + ssl_ca_path: The path to a directory containing several CA certificates in PEM format. Defaults to None. + ssl_password: Password for unlocking an encrypted private key. Defaults to None. + + Raises: + RedisError + """ # noqa if not ssl_available: raise RedisError("Python wasn't built with SSL support") @@ -910,7 +931,9 @@ class SSLConnection(Connection): ssl_cert_reqs = CERT_REQS[ssl_cert_reqs] self.cert_reqs = ssl_cert_reqs self.ca_certs = ssl_ca_certs + self.ca_path = ssl_ca_path self.check_hostname = ssl_check_hostname + self.certificate_password = ssl_password def _connect(self): "Wrap the socket with SSL support" @@ -919,9 +942,12 @@ class SSLConnection(Connection): context.check_hostname = self.check_hostname context.verify_mode = self.cert_reqs if self.certfile and self.keyfile: - context.load_cert_chain(certfile=self.certfile, keyfile=self.keyfile) - if self.ca_certs: - context.load_verify_locations(self.ca_certs) + context.load_cert_chain(certfile=self.certfile, + keyfile=self.keyfile, + password=self.certificate_password) + if self.ca_certs is not None or self.ca_path is not None: + context.load_verify_locations(cafile=self.ca_certs, + capath=self.ca_path) return context.wrap_socket(sock, server_hostname=self.host) |
