← Knowledge base

Python

Python’s ssl module wraps OpenSSL. Different Python distributions can link or bundle different OpenSSL releases, independently of the executable on your PATH.

Evidence to collect

  1. Inspect ssl.OPENSSL_VERSION using the interpreter that runs the application.
  2. Check the actual HTTP library, proxy path, SSL context, and trust configuration.
  3. SSLSocket.cipher() reports the cipher suite, not the selected key-exchange group. Treat a missing group as unknown.
  4. A local OpenSSL check establishes server capability with that tool; it does not certify requests made by Python.

Read-only inventory

Run this in the environment used by the application. Missing commands mean the tool is unavailable. This output is inventory, not a negotiation result.

python3 -c "import ssl; print(ssl.OPENSSL_VERSION)"

Record the scope and result

Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.

Official references

Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.