tlslite-ng
Pure python implementation of SSL and TLS.
Decision gist · record as of 2026-08-14
Yes, with conditions. Install if you need a pure-Python TLS implementation for testing, embedded use, or custom protocol control, and you accept the LGPLv2 copyleft constraint. The package is actively maintained, has no known vulnerabilities, and low install friction. Do not install as a drop-in replacement for the standard library ssl module in production unless you have specific requirements that justify the performance trade-off of pure Python over native code.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 2.6+ or 3.6+; optional acceleration libraries (pycrypto, m2crypto, gmp) are not required but improve performance.
- Low friction: pure Python wheel with a single runtime dependency (ecdsa).
- Actively maintained with recent commits and no known vulnerabilities.
License · maintenance · safety
LGPLv2 (copyleft) — LGPLv2 copyleft license: derivative works and modifications must be released under the same license. Suitable for open-source projects; proprietary use requires careful review or relicensing negotiation.
last release 2025-01-22 (569 days) · last repo commit 2026-08-12 · 270 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 309,270 downloads/mo, #7,758 on PyPI
Alternatives
Verify before relying
pip install tlslite-ng
from tlslite.tlsconnection import TLSConnection
from socket import socket
sock = socket()
conn = TLSConnection(sock)
conn.handshakeClientCert()- Completeness of TLS 1.3 support (description notes RFC 8446 is 'not complete')—specific gaps or limitations unknown.
- Performance characteristics relative to standard library ssl module or other pure-Python TLS implementations.
- Whether optional acceleration libraries (pycrypto, m2crypto, gmp) are still maintained and compatible with current Python versions.
What it is and what it does
tlslite-ng is a pure Python implementation of SSL and TLS protocols spanning SSLv3.0 through TLS 1.3. It handles the full TLS handshake, certificate validation, and encrypted record exchange without requiring compiled C extensions, though it can optionally use external crypto libraries (pycrypto, m2crypto, gmp) for faster cryptographic operations. The package supports a comprehensive set of modern cipher suites, elliptic-curve and post-quantum key exchange methods, and certificate types including RSA, DSA, and ECDSA.
It is intended as a drop-in replacement for the older tlslite library, offering more features and secure defaults. The single runtime dependency is ecdsa, and the package supports Python versions from 2.6 through 3.12. Because it is pure Python, it is portable and does not require system-level SSL libraries, making it useful for embedded systems, testing, and environments where the standard library ssl module is unavailable or insufficient.
Use it for
- Testing TLS implementations and protocol compliance without relying on system OpenSSL.
- Building TLS clients or servers in pure Python for embedded or resource-constrained environments.
- Implementing custom TLS handshake logic or certificate pinning (TACK support).
- Protocol fuzzing and security research on TLS behavior.
- Environments where system SSL libraries are unavailable or where fine-grained control over TLS parameters is needed.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, with conditions.
Install if you need a pure-Python TLS implementation for testing, embedded use, or custom protocol control, and you accept the LGPLv2 copyleft constraint. The package is actively maintained, has no known vulnerabilities, and low install friction. Do not install as a drop-in replacement for the standard library ssl module in production unless you have specific requirements that justify the performance trade-off of pure Python over native code.
Install
tlslite-ng on PyPI
Before you install
Low friction: pure Python wheel with a single runtime dependency (ecdsa). Actively maintained with recent commits and no known vulnerabilities. Supports a broad range of Python versions from 2.6 through 3.12.
Requires Python 2.6+ or 3.6+; optional acceleration libraries (pycrypto, m2crypto, gmp) are not required but improve performance.
License in practice
LGPLv2 copyleft license: derivative works and modifications must be released under the same license. Suitable for open-source projects; proprietary use requires careful review or relicensing negotiation.
Quickstart
pip install tlslite-ng
from tlslite.tlsconnection import TLSConnection
from socket import socket
sock = socket()
conn = TLSConnection(sock)
conn.handshakeClientCert()
Verify before relying
- Completeness of TLS 1.3 support (description notes RFC 8446 is 'not complete')—specific gaps or limitations unknown.
- Performance characteristics relative to standard library ssl module or other pure-Python TLS implementations.
- Whether optional acceleration libraries (pycrypto, m2crypto, gmp) are still maintained and compatible with current Python versions.
Package facts
| License | LGPLv2 copyleft |
| Python support | Supports the current Python release !=3.0.*,!=3.1.*,!=3.2.*,!=3.3.*,!=3.4.*,!=3.5.*,>=2.6 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packageecdsa |
| Maintenance | Actively maintained 569 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 309,270 / month, #7,758 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: GNU Lesser General Public License v2 (LGPLv2)Operating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 2Programming Language :: Python :: 2.6Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Security :: CryptographyTopic :: Software Development :: Libraries :: Python ModulesTopic :: System :: Networking |
Evidence: tlslite_ng-0.8.2-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “pure python tls implementation”
- tlslite-ngPure Python implementation of SSL/TLS protocols (SSLv3.0, TLS…
- qh3qh3 is a Python library implementing the QUIC network protocol and…
- aioquicaioquic implements QUIC and HTTP/3 network protocols for Python,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also M2Crypto · oscrypto · pure-sasl · sslpsk-pmd3 · qh3 · ecdsa · scramp · telnetlib3 · aioquic · PGPy