From dd8666efbcd5ad750b38d3563d54559f13c1b147 Mon Sep 17 00:00:00 2001 From: Sarthak Shubham Date: Sun, 27 Sep 2026 12:18:43 +0530 Subject: [PATCH] Fix #826: Suppress cryptography FFDH deprecation warning and add decrepit fallback --- asyncssh/crypto/dh.py | 29 ++++++++++++++++++++++------- 1 file changed, 22 insertions(+), 7 deletions(-) diff --git a/asyncssh/crypto/dh.py b/asyncssh/crypto/dh.py index 52e09e7e..554f0b2a 100644 --- a/asyncssh/crypto/dh.py +++ b/asyncssh/crypto/dh.py @@ -20,27 +20,42 @@ """A shim around PyCA for Diffie Hellman key exchange""" -from cryptography.hazmat.primitives.asymmetric import dh +import warnings +from cryptography.utils import CryptographyDeprecationWarning + +try: + from cryptography.hazmat.primitives.asymmetric import dh +except ImportError: + from cryptography.hazmat.decrepit.asymmetric import dh class DH: """A shim around PyCA for Diffie Hellman key exchange""" def __init__(self, g: int, p: int): - self._pn = dh.DHParameterNumbers(p, g) - self._priv_key = self._pn.parameters().generate_private_key() + with warnings.catch_warnings(): + warnings.simplefilter('ignore', CryptographyDeprecationWarning) + + self._pn = dh.DHParameterNumbers(p, g) + self._priv_key = self._pn.parameters().generate_private_key() def get_public(self) -> int: """Return the public key to send in the handshake""" - pub_key = self._priv_key.public_key() + with warnings.catch_warnings(): + warnings.simplefilter('ignore', CryptographyDeprecationWarning) + + pub_key = self._priv_key.public_key() - return pub_key.public_numbers().y + return pub_key.public_numbers().y def get_shared(self, peer_public: int) -> int: """Return the shared key from the peer's public key""" - peer_key = dh.DHPublicNumbers(peer_public, self._pn).public_key() - shared_key = self._priv_key.exchange(peer_key) + with warnings.catch_warnings(): + warnings.simplefilter('ignore', CryptographyDeprecationWarning) + + peer_key = dh.DHPublicNumbers(peer_public, self._pn).public_key() + shared_key = self._priv_key.exchange(peer_key) return int.from_bytes(shared_key, 'big')