credential_store

File-based credential store for TekHSI TLS trust and Basic auth.

CertInfo dataclass

CertInfo(cert_fingerprint: str, cert_pem: bytes | None = None, tls_server_name: str | None = None)

Certificate fingerprint and optional PEM for trust-on-first-use.

fingerprint property

fingerprint: str

Alias for cert_fingerprint (API doc naming).

from_pem staticmethod

from_pem(cert_pem: bytes) -> CertInfo

Build CertInfo from certificate PEM bytes (e.g. from TLS handshake).

TekHSICredentialStore

TekHSICredentialStore(path: str | None = None)

INI-backed store for per-host TLS trust and Basic-auth credentials.

get

get(host: str) -> dict[str, str | None] | None

Return entry for host or None if not found.

list_hosts

list_hosts() -> list[str]

Return all stored host keys.

load

load() -> None

Load store from file. No-op if file does not exist.

remove

remove(host: str) -> None

Remove entry for host.

save

save() -> None

Write store atomically (temp + rename). Creates parent directory if needed.

set

set(
    host: str,
    cert_fingerprint: str | None = None,
    cert_path: str | None = None,
    tls_server_name: str | None = None,
    login: str | None = None,
    password: str | None = None,
) -> None

Write or update entry for host. Omitted keys left unchanged; explicit None clears.

trust

trust(
    host: str, cert_info: CertInfo, password: str | None = None, login: str | None = None
) -> None

Record trust for host: fingerprint, optional cert file, password, and optional login.

tls_server_name_from_pem

tls_server_name_from_pem(cert_pem: bytes) -> str | None

Return TLS verification name from server cert PEM (SAN DNS, else CN).