Repository navigation
Pass explicit empty trust roots to pyHanko signature validation - #1
Merged
Merged
Conversation
pyhanko-certvalidator 0.32 deprecated the implicit fall-back to the operating system's TLS trust list when no trust roots are given, and warns that it will stop working in a future release. Every signature validation triggered that DeprecationWarning. The signatures analyser checks integrity and post-signing modifications, not signer trust (the finding text already says trust roots are not configured by default), and OS TLS roots are not a document-signing trust source in any case. Passing a ValidationContext with an empty trust_roots list makes that explicit and silences the warning. Certificate trust continues to be reported by the pdfsig cross-check. Findings for the bank-statement examples are unchanged. Adds a test that fails if the deprecation warning returns.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Every signature validation emitted a DeprecationWarning from pyhanko-certvalidator 0.32:
The signatures analyser only uses pyHanko for integrity and post-signing modification checks. The
signature.intactfinding already states that trust roots are not configured by default, and the OS TLS trust list is not a meaningful source for document-signing trust anyway. This change passesValidationContext(trust_roots=[])so that intent is explicit, and the code keeps working when pyHanko removes the fall-back.Certificate trust is still reported by the
pdfsigcross-check, as before.Changes
analyzers/signatures.py: pass an explicit empty trust-root list tovalidate_pdf_signature.tests/test_analysis.py: new test that fails if the trust-list deprecation warning returns, and checks thattrustedis reported asFalse.Testing
pytest: 104 passed, also with-W error::DeprecationWarning.intact,valid,trusted,modification_level,docmdp_ok) are identical.Tested with pyHanko 0.37.0 and pyhanko-certvalidator 0.32.1 on Python 3.13.