Repository navigation
asyncio SSL not sending TLS Fatal Alerts #98078
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Oct 8, 2022 Can you test Python 3.11 and main branch?
Or if you wanted us to test this you'll have to attach the cert, key and ca files that the demo program references -- I am not going to learn how to set up an SSL web server myself.
- addedpendingThe issue will be closed if no feedback is providedThe issue will be closed if no feedback is provided
on Oct 9, 2022 Attached is a zip file containing the necessary files.
I'll attempt to test 3.11 and main right now.
@kumaraditya303 3.11 exhibits the same behavior. It's also worth noting I also tried the ssl's library newer method for configuring versions via the
ssl_ctx.minimum_versionandssl_ctx.maximum_versionfields.I suspect that only an SSL/Python expert like @tiran can help us with this...
The alert message never reaches the client because asyncio does not flush the outgoing buffer with
self._process_outgoing()onSSLError._do_shutdownhas the same bug.Someone who understands those words would need to come up with a PR. Please?
The alert message never reaches the client because asyncio does not flush the outgoing buffer with
self._process_outgoing()onSSLError._do_shutdownhas the same bug.Bless. We're using Python 3.7.14, which appears to be an older SSL implementation. I added a quick patch to ours to check the outgoing buffer and write it to the transport when handling a SSLError exception in _on_handshake_complete - and we're now successfully sending alerts.
I could do a formal PR here with the newer SSL implementation (v11) since it should be much easier with the _process_outgoing() API. I could try one for versions 7 through 10 as well.
If you could submit a PR, ideally one containing a new test that fails without the patch, that would be fantastic!
Sounds good. I'll leaving on vacation this weekend, so I'll try to get a PR up in 1-2 weeks.
- removedpendingThe issue will be closed if no feedback is providedThe issue will be closed if no feedback is provided
on Oct 12, 2022 Looks like @stevoleeto isn't coming from that vacation..
I think what @tiran meant is that there's a need to call
self._do_flush()somewhere inand maybecpython/Lib/asyncio/sslproto.py
Lines 718 to 723 in 21ed1e2
def _process_outgoing(self): if not self._ssl_writing_paused: data = self._outgoing.read() if len(data): self._transport.write(data) self._control_app_writing() (although, I'm not sure).cpython/Lib/asyncio/sslproto.py
Lines 648 to 659 in 21ed1e2
def _do_shutdown(self): try: if not self._eof_received: self._sslobj.unwrap() except SSLAgainErrors: self._process_outgoing() except ssl.SSLError as exc: self._on_shutdown_complete(exc) else: self._process_outgoing() self._call_eof_received() self._on_shutdown_complete(None) - added a commit that references this issue
on Jul 14, 2026 - added3.16new features, bugs and security fixesnew features, bugs and security fixes
on Jul 14, 2026
Metadata
Metadata
Assignees
Labels
Projects
- StatusShow more project fieldsDone
Bug report
We're using the python3-uvicorn package to host a web server, and are running into an issue with TLS RFC compliance in which Fatal alerts are not being sent. The issue we're examining in particular is when the client / server cannot agree on a TLS protocol version.
Inspecting the issue further, we believe the issue is with the SSL protocol implementation in the asyncio module. Using the native Python SSL module itself we see alerts being sent, however when using asyncio we're not seeing any alerts.
As far as I'm concerned, this should be easy to reproduce. Firefox shows a "PR_END_OF_FILE_ERROR" instead of the expected "SSL_ERROR_PROTOCOL_VERSION_ALERT". I have attached the simple asyncio server I'm using to demonstrate this. Using Firefox and configuring a TLS option which is invalid with the simple server will replicate the issue.
asyncio_web.py.txt
Any help or clarity here would be greatly appreciated!
Your environment
Linked PRs