# SSL/TLS Configuration Options in you-get: A Complete Guide to Secure Downloading

> Explore SSL TLS configuration options in you-get. Learn to use the insecure flag and custom SSLContext for secure and compatible downloads.

- Repository: [Mort Yao/you-get](https://github.com/soimort/you-get)
- Tags: how-to-guide
- Published: 2026-03-06

---

**you-get provides two distinct SSL/TLS control mechanisms: the global `--insecure` (`-k`) flag to disable certificate verification entirely, and per-extractor custom `SSLContext` objects that enforce specific TLS protocol versions for compatibility with restrictive servers.**

The `you-get` download utility handles HTTPS traffic through Python's `urllib` stack, exposing targeted SSL/TLS configuration options for both global and site-specific scenarios. Whether you need to bypass certificate errors on misconfigured servers or force legacy TLS versions for compatibility, the codebase offers precise controls via command-line flags and extractor-level implementations in [`src/you_get/common.py`](https://github.com/soimort/you-get/blob/main/src/you_get/common.py) and individual extractor modules.

## Global Certificate Verification Control (--insecure)

### Disabling Verification for All Requests

The most common SSL/TLS configuration option is the `--insecure` (or `-k`) flag, defined in [`src/you_get/common.py`](https://github.com/soimort/you-get/blob/main/src/you_get/common.py) around line 46. When invoked, this sets the global flag `insecure = True`, which propagates through the library's HTTP helper functions to disable certificate validation for every subsequent request.

When `insecure` is enabled, the `get_response()` and `urlopen_with_retry()` functions create a custom `ssl.SSLContext` with `verify_mode = ssl.CERT_NONE` and `check_hostname = False`. This context is passed to `urllib.request.urlopen()`, effectively bypassing SSL certificate verification warnings and errors.

```bash

# Download content while ignoring SSL certificate errors

you-get -k "https://expired-cert.example.com/video"
you-get --insecure "https://self-signed.example.com/media"

```

Internally, the flag triggers this logic pattern across network calls:

```python

# Conceptual implementation from src/you_get/common.py

if insecure:
    ssl_context = ssl.SSLContext()
    ssl_context.verify_mode = ssl.CERT_NONE
    ssl_context.check_hostname = False
    response = urlopen(url, context=ssl_context)

```

## Per-Extractor TLS Version Enforcement

### Forcing TLS 1.2 for Specific Sites

Some remote servers reject Python's default TLS negotiation and require a specific protocol version. The Tumblr extractor in [`src/you_get/extractors/tumblr.py`](https://github.com/soimort/you-get/blob/main/src/you_get/extractors/tumblr.py) demonstrates this by explicitly building an `SSLContext` with `ssl.PROTOCOL_TLSv1_2` and injecting it into a custom `HTTPSHandler`.

```python

# Implementation from src/you_get/extractors/tumblr.py

import ssl
from urllib import request

# Build a handler that forces TLS v1.2

ssl_context = request.HTTPSHandler(context=ssl.SSLContext(ssl.PROTOCOL_TLSv1_2))
opener = request.build_opener(ssl_context, cookie_handler)
request.install_opener(opener)

# Subsequent requests for Tumblr use TLS 1.2 exclusively

response = request.urlopen(tumblr_api_url)

```

This approach overrides the default TLS version only for that specific extractor, leaving other requests unaffected.

### Legacy TLS Support for Restricted Endpoints

When servers mandate older TLS versions, extractors like NicoVideo and InfoQ force TLS 1.0 through similar context construction. The [`src/you_get/extractors/nicovideo.py`](https://github.com/soimort/you-get/blob/main/src/you_get/extractors/nicovideo.py) module implements this pattern to maintain connectivity with legacy infrastructure.

```python

# Implementation from src/you_get/extractors/nicovideo.py

ssl_context = request.HTTPSHandler(
    context=ssl.SSLContext(ssl.PROTOCOL_TLSv1)
)
opener = request.build_opener(ssl_context, cookie_handler)
request.install_opener(opener)

```

The [`src/you_get/extractors/infoq.py`](https://github.com/soimort/you-get/blob/main/src/you_get/extractors/infoq.py) module employs an identical strategy, demonstrating that this is the standard pattern within the codebase for handling TLS version mismatches on a per-site basis.

## How SSL Contexts Are Applied

The application of these SSL/TLS configuration options follows a clear hierarchy:

- **Default behavior**: Uses Python's standard SSL verification with the system's CA bundle and default TLS version
- **Global `--insecure` flag**: Creates unverified contexts via `ssl.SSLContext()` with disabled verification in [`common.py`](https://github.com/soimort/you-get/blob/main/common.py)
- **Per-extractor contexts**: Build custom `HTTPSHandler` objects with specific `SSLContext` protocol versions, assembled through `request.build_opener()` and activated via `request.install_opener()`

This architecture allows `you-get` to maintain secure defaults while providing escape hatches for both global connectivity issues (via the CLI flag) and specific site requirements (via extractor code).

## Summary

- The `--insecure` (`-k`) flag globally disables SSL certificate verification by setting `verify_mode = ssl.CERT_NONE` in [`src/you_get/common.py`](https://github.com/soimort/you-get/blob/main/src/you_get/common.py)
- Individual extractors can enforce specific TLS versions using custom `SSLContext` objects with explicit protocol selection (TLS 1.0, 1.2, etc.)
- Tumblr, NicoVideo, and InfoQ extractors demonstrate per-site TLS configuration via `HTTPSHandler` and `build_opener()` patterns
- Default behavior relies on Python's standard certificate verification and TLS negotiation

## Frequently Asked Questions

### How do I bypass SSL certificate errors when downloading with you-get?

Use the `-k` or `--insecure` command-line flag. According to the source code in [`src/you_get/common.py`](https://github.com/soimort/you-get/blob/main/src/you_get/common.py), this sets a global flag that creates SSL contexts with `ssl.CERT_NONE` and disabled hostname checking, allowing connections to servers with expired or self-signed certificates.

### Can I force a specific TLS version like 1.2 for all downloads?

The command-line interface does not expose a global TLS version selector. However, individual extractors in `src/you_get/extractors/` (such as Tumblr) implement site-specific TLS 1.2 enforcement by constructing custom `SSLContext` objects with `ssl.PROTOCOL_TLSv1_2` and installing them via `urllib.request.build_opener()`.

### Why does you-get use different SSL configurations for different sites?

Some legacy servers or restrictive CDNs reject modern TLS handshakes and require specific protocol versions (like TLS 1.0 or 1.2). The per-extractor SSL contexts in files like [`src/you_get/extractors/nicovideo.py`](https://github.com/soimort/you-get/blob/main/src/you_get/extractors/nicovideo.py) override the default negotiation to maintain compatibility without compromising security for other requests.

### Is the `--insecure` flag safe to use?

The `--insecure` flag disables certificate verification entirely, which protects against connection failures but removes protection against man-in-the-middle attacks. As implemented in [`src/you_get/common.py`](https://github.com/soimort/you-get/blob/main/src/you_get/common.py), this sets `check_hostname = False` and `verify_mode = ssl.CERT_NONE`, so use it only when accessing trusted servers with known certificate issues.