In a previous hackweek project ( I have converted osc code to Python3. This has triggered quite some weirdness regarding plugins, but osc is usable from python3. Or it was, not sure if more recent changes did not break the compatibility.

The task

But usable means, you can run osc if you don't need to bother with ssl. Which you need to, so osc3 is barely usable in a real world. osc interfaces with openssl through M2Crypto, which lacks python3 version. At the same time, python3 got much better support for ssl. So task would be to evaluate the most easy way to switch osc's ssl to python3.


There were three possible ways I have had analyzed.

  1. Use python.ssl module, which would be the most viable approach.
  2. Check the existence of much better module
  3. Port M2Crypto to python3

Python ssl module does provide a nice HTTPSConnection classes. But it is mostly incompatible with python 2.6.x ssl module, so one would need to use M2Crypto for python2 and ssl for python3, which would means two codepaths. But the ship stopper was the fact M2Crypto allows to work with X509 certificates stored in ~/.config/osc/trusted-certs/, where I did not find an alternative functionality in ssl module. A short attempt to write own X509 handling code using python-cffi showed me that OpenSSL is much more complex library than one would thing. And with almost no documentation or comments in source code.

I was not successful with a looking for much better ssl module. And there are none as far as I know. The most promising project is, but not finished and not dealing with X509 certs. An another opinion was, but it seems more like alex's learning project before contributing to cryptography.

So the last remaining option was to port M2Crypto to Python 3.


I have found the related bug report and realized that Matěj Cepl from RedHat made an initial effort. So I have forked his repository and made some nice progress, which unfortunately means that all low-hanging fruits are now fixed.

What I learned

  • much much much more details about Python3 internals and how it is different from Python2 (especially IO). I can recommend to take a look at
  • some limited ability to write a code in SWIG
  • much much much much more about OpenSSL and how hard is to get into, because of a complexity and lack of docs
  • the fact that in a month when last python 2 interpreter release will appear (Oct 2013), there is no good and powerful OpenSSL binding available

Looking for hackers with the skills:

python3 python openssl c

This project is part of:

Hack Week 10


  • over 8 years ago: mvyskocil added keyword "python3" to this project.
  • over 8 years ago: mvyskocil added keyword "python" to this project.
  • over 8 years ago: mvyskocil added keyword "openssl" to this project.
  • over 8 years ago: mvyskocil added keyword "c" to this project.
  • over 8 years ago: mvyskocil started this project.
  • over 8 years ago: mvyskocil originated this project.

  • Comments

    Be the first to comment!

    Similar Projects

    Cluster Python API by fmherschel

    [comment]: # (Please use the project descriptio...

    Anomaly analyser, predictor for kubernetes(Rancher) by sbabusadhu

    [comment]: # (Please use the project descriptio...

    Uyuni/SUSE Manager: build Python APE and a Salt+Python bundle to support ANY client operating system by pagarcia

    Uyuni/SUSE Manager build client tools for each ...

    YAML 1.2 Schema support for PyYAML by tinita

    [comment]: # (Please use the project descriptio...

    Develop a monitoring system with web frontend for virtualization servers by nzhang

    [comment]: # (Please use the project descriptio...

    Script that loads dummy data into HANA database for testing purposes. by rangelino

    [comment]: # (Please use the project descriptio...

    Learn python by building a homepage with Flask by mbrugger

    I thought it would be time to learn a new progr...

    One of couple of Python projects by mcepl

    There are couple of projects I work on, which n...

    Phoebe - where AI meets Linux by mvarlese

    Project Description

    Phoeβe (/ˈfiːbi/) wan...

    multipath-tools: cleaner model for path device information by mwilck

    Project Description

    Obtaining correct inf...

    multipathd: improve asynchronous behavior by mwilck

    Project Description

    multipathd is multi...

    multipath-tools: improve CI by mwilck

    Project Description

    multipath-tools is ...

    multithreaded network benchmark by mkubecek

    Project Description

    There are multiple ne...