TLS parameters example¶
This example demonstrates a TLS session with RabbitMQ using server authentication.
See TLS Support for certificate creation and RabbitMQ TLS configuration instructions.
examples/tls_server_authentication.py:
import logging
import ssl
import pika
logging.basicConfig(level=logging.INFO)
context = ssl.create_default_context(
cafile='/Users/me/tls-gen/basic/result/ca_certificate.pem')
context.verify_mode = ssl.CERT_REQUIRED
context.load_cert_chain('/Users/me/tls-gen/result/client_certificate.pem',
'/Users/me/tls-gen/result/client_key.pem')
ssl_options = pika.SSLOptions(context, 'localhost')
conn_params = pika.ConnectionParameters(port=5671, ssl_options=ssl_options)
with pika.BlockingConnection(conn_params) as conn:
ch = conn.channel()
print(ch.queue_declare('sslq'))
ch.basic_publish('', 'sslq', b'abc')
print(ch.basic_get('sslq'))
%% In this example, both the client and RabbitMQ server are assumed to be running on the same machine
%% with a self-signed set of certificates generated using https://github.com/rabbitmq/tls-gen.
%%
%% To find out the default rabbitmq.conf location, see https://www.rabbitmq.com/configure.html.
%%
%% The contents of the example config file are for demonstration purposes only.
%% See https://www.rabbitmq.com/ssl.html to learn how to use TLS for client connections in RabbitMQ.
%%
%% The example below allows clients without a certificate to connect
%% but performs peer verification on those that present a certificate chain.
listeners.ssl.default = 5671
ssl_options.cacertfile = /Users/me/tls-gen/basic/result/ca_certificate.pem
ssl_options.certfile = /Users/me/tls-gen/basic/result/server_certificate.pem
ssl_options.keyfile = /Users/me/tls-gen/basic/result/server_key.pem
ssl_options.verify = verify_peer
ssl_options.fail_if_no_peer_cert = false