Skip to content

Support passwords for encrypted SSL client keys - #28

Merged
skhe merged 1 commit into
mainfrom
codex/ssl-encrypted-client-key
Sep 26, 2026
Merged

skhe merged 1 commit into
mainfrom
codex/ssl-encrypted-client-key

Conversation

@skhe

@skhe skhe commented Sep 26, 2026

Copy link
Copy Markdown
Owner

Summary

  • Pass ssl_pwd from the Python DPI interface through the Go connector to TLS.
  • Decrypt traditional encrypted PEM client keys; reject missing or wrong passwords and unsupported encrypted PKCS#8 keys explicitly.
  • Keep UKey unsupported rather than silently opening a different connection.

Verification

  • Local ARM macOS Python 3.10 against SSL-enabled DM8: all five SSL tests passed, including an encrypted RSA client key with a password containing +, &, and a space.
  • Ordinary DM8: ssl_pwd without ssl_path rejected as expected.
  • Go TLS security tests, Go bridge tests, patch consistency check, Python 3.9 syntax compilation, and git diff --check passed.

Encrypted PKCS#8 private keys remain unsupported and are reported clearly.

@skhe
skhe merged commit 1a5b573 into main Sep 26, 2026
19 checks passed
@skhe
skhe deleted the codex/ssl-encrypted-client-key branch September 26, 2026 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant