PyCA cryptography 50.0.0 has been released to PyPI. cryptography
includes both high level recipes and low level interfaces to common
cryptographic algorithms such as symmetric ciphers, asymmetric
algorithms, message digests, X.509, key derivation functions, and much
more. We support Python 3.9+, and PyPy3 3.11.

Changelog (https://cryptography.io/en/latest/changelog/#v50-0-0)
* SECURITY ISSUE: pkcs7_decrypt_der and its PEM and S/MIME variants no
longer expose distinguishable errors or timing when unwrapping a
RecipientInfo's encryptedKey, which could act as a Bleichenbacher
oracle for callers that decrypt untrusted messages. A random key is
now substituted on failure, as described in RFC 3218. Credit to
@X1AOxiang for reporting the issue
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
Everything FFDH is deprecated, including the types in
cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or
parameters with the key loading APIs. Users should migrate to a more
modern key exchange algorithm.
* Added xof() class methods to SHAKE128 and SHAKE256 for constructing
algorithm instances configured for use with XOFHash.
* The X.509 verification APIs are now considered stable and are
subject to our API stability policy.
* Added the Cobblestone recipe, an implementation of the
Cobblestone-128 and Cobblestone-256 instantiations of the C2SP
chunked-encryption specification (https://c2sp.org/chunked-encryption)
for streaming authenticated encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings
that carry trailing bytes after the list or after an individual SCT,
instead of silently ignoring them.
* Added support for using x509.Name as a field type in the
cryptography.hazmat.asn1 module.
* Loading a public key or an EC private key now rejects DER where the
subjectPublicKey (or EC publicKey) BIT STRING declares a non-zero
number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's InvalidityDate extension now rejects a
GeneralizedTime that carries fractional seconds or another non-DER
form, matching the strict encoding already required for every other
X.509 time field.
* load_der_ocsp_request and load_der_ocsp_response now reject a
request or response whose version field is not v1, the only version
defined by RFC 6960, matching the version validation already performed
when loading certificates, CSRs and CRLs.
* XOFHash is now supported when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported
when building against AWS-LC.
* Diffie-Hellman is now supported when building against AWS-LC.
* load_der_public_key and load_pem_public_key now reject
Diffie-Hellman public keys whose modulus is smaller than 512 bits,
matching the minimum already enforced when loading DH private keys and
when constructing DHParameterNumbers.
* Added MLDSAMuHasher for incrementally computing the ML-DSA mu
(message representative) used by the external-mu signing and
verification APIs.
* The builtin HashAlgorithm classes and the classes in
cryptography.hazmat.primitives.asymmetric.padding can now be compared
with ==.
* CertificateBuilder now supports creating unsigned certificates (RFC
9925) with the create_unsigned method.
* The X.509 verification APIs now permit ML-DSA-44, ML-DSA-65, and
ML-DSA-87 (RFC 9881) public keys and signatures by default.

Alex
-- 
All that is necessary for evil to succeed is for good people to do nothing.
_______________________________________________
Cryptography-dev mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/cryptography-dev.python.org
Member address: [email protected]

Reply via email to