Coverage for /usr/local/lib/python3.10/site-packages/opal_common-0.0.0-py3.10.egg/opal_common/security/sslcontext.py: 21%
16 statements
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-10 11:54 +0000
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-10 11:54 +0000
1import os
2import ssl
3from typing import Optional
5from opal_common.config import opal_common_config
8def get_custom_ssl_context() -> Optional[ssl.SSLContext]:
9 """Potentially (if enabled), returns a custom ssl context that respect
10 self-signed certificates.
12 More accurately, may return an ssl context that respects a local CA
13 as a valid issuer.
14 """
15 if not opal_common_config.CLIENT_SELF_SIGNED_CERTIFICATES_ALLOWED:
16 return None
18 ca_file: Optional[str] = opal_common_config.CLIENT_SSL_CONTEXT_TRUSTED_CA_FILE
20 if ca_file is None:
21 return None
23 if not ca_file:
24 return None
26 ca_file_path = os.path.expanduser(ca_file)
27 if not os.path.isfile(ca_file_path):
28 return None
30 return ssl.create_default_context(cafile=ca_file_path)