wassima
Access your OS root certificates with utmost ease
Decision gist · record as of 2026-08-14
Yes. Wassima is actively maintained, has no dependencies, installs cleanly, carries a permissive MIT license, and solves a real problem—accessing the OS trust store without bundling a static copy. It's a solid drop-in for certifi in projects that want to respect system certificate policy. No known vulnerabilities.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.7 or later; PyPy is supported.
- Low friction: pure Python wheel with no runtime dependencies.
- Actively maintained with a recent release (21 days ago) and last commit on 2026-08-01.
License · maintenance · safety
MIT (permissive) — MIT license (permissive) means you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.
last release 2026-07-24 (21 days) · last repo commit 2026-08-01 · 24 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,954,835 downloads/mo, #3,410 on PyPI
Alternatives
Verify before relying
pip install wassima
import wassima
ctx = wassima.create_default_ssl_context()
# ctx now contains your system root CAs
bundle = wassima.generate_ca_bundle()
# bundle is a string with all root CAs in PEM format- Whether the embedded CCADB bundle is updated regularly and how frequently
- Performance characteristics when hybrid_store=True on systems with large trust stores
- Exact behavior of the 3-year staleness check on Linux/BSD systems
What it is and what it does
Wassima is a certificate store abstraction layer that reads your operating system's root CA certificates and makes them available in multiple formats (SSL context, DER, PEM, or concatenated bundle). It automatically falls back to an embedded CCADB-sourced trust store when the OS provides nothing, and supports a hybrid mode that combines both for environments like containers where the system store may be outdated or incomplete. The library caches results for performance (default 12-hour TTL) and deduplicates certificates across multiple OS store locations.
It's designed as a permissive-licensed alternative to certifi, letting you work with your actual system trust store rather than a static bundled copy. You can register additional CAs, control cache behavior, and force hybrid mode when needed. The package works out-of-the-box on any OS and supports Python 3.7+ including PyPy.
Use it for
- Build HTTPS clients that respect the system's certificate policy without bundling a separate CA store
- Create SSL contexts in containers or appliances where the system trust store is slim or outdated
- Register custom root CAs alongside system certificates for internal PKI environments
- Generate CA bundles for tools that need PEM-format certificate files
- Ensure certificate verification picks up OS-level CA updates without restarting the application
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Wassima is actively maintained, has no dependencies, installs cleanly, carries a permissive MIT license, and solves a real problem—accessing the OS trust store without bundling a static copy. It's a solid drop-in for certifi in projects that want to respect system certificate policy. No known vulnerabilities.
Install
wassima on PyPI
Before you install
Low friction: pure Python wheel with no runtime dependencies. Actively maintained with a recent release (21 days ago) and last commit on 2026-08-01. Supports Python 3.7+ and PyPy.
Requires Python 3.7 or later; PyPy is supported.
License in practice
MIT license (permissive) means you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.
Quickstart
pip install wassima
import wassima
ctx = wassima.create_default_ssl_context()
# ctx now contains your system root CAs
bundle = wassima.generate_ca_bundle()
# bundle is a string with all root CAs in PEM format
Verify before relying
- Whether the embedded CCADB bundle is updated regularly and how frequently
- Performance characteristics when hybrid_store=True on systems with large trust stores
- Exact behavior of the 3-year staleness check on Linux/BSD systems
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 21 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 1,954,835 / month, #3,410 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.15Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Internet :: WWW/HTTPTopic :: Software Development :: Libraries |
Evidence: wassima-2.1.3-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “os root certificates ssl”
- wassimaWassima provides access to your operating system's root certificate…
- pip-system-certsAutomatically configures Python to use the operating system's…
- certifiCertifi provides Mozilla's curated collection of root SSL…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also certifi-linux · truststore · certifi · mscerts · wincertstore · python-certifi-win32 · pip-system-certs · trustme · secure-smtplib · mitmproxy-macos