wincertstore
Python module to extract CA and CRL certs from Windows' cert store (ctypes based).
Decision gist · record as of 2026-08-14
No. The package is abandoned, deprecated by design, and incompatible with Python 3.4+. Modern Python (2.7.9+) handles Windows certificate stores automatically via ssl.create_default_context(). Install only if you are maintaining legacy Python 2.7 code that predates this built-in behavior and cannot upgrade.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Windows XP or newer required; Windows-only (uses crypt32.dll).
- Not compatible with Python 3.4+.
- Low install friction, but the package is abandoned as of 2021 and deprecated by design—Python 2.7.9+ and modern Python 3 versions handle Windows cert stores automatically via ssl.create_default_context().
License · maintenance · safety
PSFL (permissive) — Licensed under the Python Software Foundation License (PSFL), a permissive license. No restrictions on use, modification, or distribution for most purposes.
last release 2021-06-08 (1893 days) · last repo commit 2021-06-28 · 1 stars · archived
0 known vulnerabilities (OSV.dev, 2026-08-14) · 395,270 downloads/mo, #6,983 on PyPI
Alternatives
Verify before relying
import wincertstore
for storename in ("CA", "ROOT"):
with wincertstore.CertSystemStore(storename) as store:
for cert in store.itercerts(usage=wincertstore.SERVER_AUTH):
print(cert.get_pem().decode("ascii"))
print(cert.get_name())- Whether the package works reliably on modern Windows versions (last release 2021-06-08, no recent maintenance).
- Current compatibility with Python 3.3 given the requires_python constraint excludes 3.4+.
What it is and what it does
wincertstore is a Windows-specific library that provides direct access to the operating system's certificate stores (CA and CRL) using ctypes to call the Windows crypt32.dll API. It allows you to enumerate certificates from Windows' system stores, filter them by enhanced key usage (such as SERVER_AUTH or CLIENT_AUTH), and extract them in PEM format or as a temporary certificate file for use with Python's ssl module.
The package is explicitly deprecated: since Python 2.7.9, the standard library's ssl.create_default_context() automatically loads certificates from Windows' cert store, making this package unnecessary for most modern use cases. The project is abandoned (last commit 2021-06-28, repository archived), and it targets only Python 2.7 and Python 3.0–3.3, making it incompatible with current Python versions.
Use it for
- Extract CA certificates from Windows system store for legacy Python 2.7 applications that predate automatic cert loading.
- Access CRL (Certificate Revocation List) certificates from Windows' cert store in older codebases.
- Build a temporary certificate bundle file from Windows system stores for use with ssl.wrap_socket on Python 2.7.
- Enumerate certificates by enhanced key usage (e.g., SERVER_AUTH, CLIENT_AUTH) on Windows in pre-2.7.9 Python environments.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
The package is abandoned, deprecated by design, and incompatible with Python 3.4+. Modern Python (2.7.9+) handles Windows certificate stores automatically via ssl.create_default_context(). Install only if you are maintaining legacy Python 2.7 code that predates this built-in behavior and cannot upgrade.
Install
wincertstore on PyPI
Before you install
Low install friction, but the package is abandoned as of 2021 and deprecated by design—Python 2.7.9+ and modern Python 3 versions handle Windows cert stores automatically via ssl.create_default_context().
Windows XP or newer required; Windows-only (uses crypt32.dll). Not compatible with Python 3.4+.
License in practice
Licensed under the Python Software Foundation License (PSFL), a permissive license. No restrictions on use, modification, or distribution for most purposes.
Quickstart
import wincertstore
for storename in ("CA", "ROOT"):
with wincertstore.CertSystemStore(storename) as store:
for cert in store.itercerts(usage=wincertstore.SERVER_AUTH):
print(cert.get_pem().decode("ascii"))
print(cert.get_name())
Verify before relying
- Whether the package works reliably on modern Windows versions (last release 2021-06-08, no recent maintenance).
- Current compatibility with Python 3.3 given the requires_python constraint excludes 3.4+.
Package facts
| License | PSFL permissive |
| Python support | Not specified >=2.7,!=3.0.*,!=3.1.*,<3.4.* |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Abandoned 1,893 days since the last release |
| Last repo commit | repository archived |
| First released | |
| Downloads | 395,270 / month, #6,983 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: Python Software Foundation LicenseNatural Language :: EnglishOperating System :: Microsoft :: WindowsProgramming Language :: PythonProgramming Language :: Python :: 2Programming Language :: Python :: 2.7Programming Language :: Python :: 3 |
Evidence: wincertstore-0.2.1-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “windows certificate store access”
- wincertstoreAccesses Windows system certificate stores (CA and CRL) via ctypes…
- mscertsProvides access to Microsoft's Root Certificate Authorities bundle…
- python-certifi-win32Patches certifi at runtime to include certificates from the Windows…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also certifi-linux · python-certifi-win32 · trustme · secure-smtplib · mscerts · wassima · pip-system-certs · truststore · certipy