Allow configuration of SSL Ciphers #1755
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Additional support for #1741 . While testing SSL connections w/ python3.7 locally, I found that the default ssl ciphers that my python3.7 install supported were not sufficient to establish a connection with my kafka broker. This PR adds a new configuration option
ssl_ciphers
that will be passed through toSSLContext.set_ciphers()
and may allow use of ciphers that are available but not enabled by default on a particular python / openssl installation. In my case, this wasDHE-DSS-AES128-GCM-SHA256
. Without this configuration, my connection attempts failed with ssl.SSLErrorUNKNOWN_PROTOCOL
This change is