SSL/TLS Configuration Options in you-get: A Complete Guide to Secure Downloading
you-get provides two distinct SSL/TLS control mechanisms: the global --insecure (-k) flag to disable certificate verification entirely, and per-extractor custom SSLContext objects that enforce specific TLS protocol versions for compatibility with restrictive servers.
The you-get download utility handles HTTPS traffic through Python's urllib stack, exposing targeted SSL/TLS configuration options for both global and site-specific scenarios. Whether you need to bypass certificate errors on misconfigured servers or force legacy TLS versions for compatibility, the codebase offers precise controls via command-line flags and extractor-level implementations in src/you_get/common.py and individual extractor modules.
Global Certificate Verification Control (--insecure)
Disabling Verification for All Requests
The most common SSL/TLS configuration option is the --insecure (or -k) flag, defined in src/you_get/common.py around line 46. When invoked, this sets the global flag insecure = True, which propagates through the library's HTTP helper functions to disable certificate validation for every subsequent request.
When insecure is enabled, the get_response() and urlopen_with_retry() functions create a custom ssl.SSLContext with verify_mode = ssl.CERT_NONE and check_hostname = False. This context is passed to urllib.request.urlopen(), effectively bypassing SSL certificate verification warnings and errors.
# Download content while ignoring SSL certificate errors
you-get -k "https://expired-cert.example.com/video"
you-get --insecure "https://self-signed.example.com/media"
Internally, the flag triggers this logic pattern across network calls:
# Conceptual implementation from src/you_get/common.py
if insecure:
ssl_context = ssl.SSLContext()
ssl_context.verify_mode = ssl.CERT_NONE
ssl_context.check_hostname = False
response = urlopen(url, context=ssl_context)
Per-Extractor TLS Version Enforcement
Forcing TLS 1.2 for Specific Sites
Some remote servers reject Python's default TLS negotiation and require a specific protocol version. The Tumblr extractor in src/you_get/extractors/tumblr.py demonstrates this by explicitly building an SSLContext with ssl.PROTOCOL_TLSv1_2 and injecting it into a custom HTTPSHandler.
# Implementation from src/you_get/extractors/tumblr.py
import ssl
from urllib import request
# Build a handler that forces TLS v1.2
ssl_context = request.HTTPSHandler(context=ssl.SSLContext(ssl.PROTOCOL_TLSv1_2))
opener = request.build_opener(ssl_context, cookie_handler)
request.install_opener(opener)
# Subsequent requests for Tumblr use TLS 1.2 exclusively
response = request.urlopen(tumblr_api_url)
This approach overrides the default TLS version only for that specific extractor, leaving other requests unaffected.
Legacy TLS Support for Restricted Endpoints
When servers mandate older TLS versions, extractors like NicoVideo and InfoQ force TLS 1.0 through similar context construction. The src/you_get/extractors/nicovideo.py module implements this pattern to maintain connectivity with legacy infrastructure.
# Implementation from src/you_get/extractors/nicovideo.py
ssl_context = request.HTTPSHandler(
context=ssl.SSLContext(ssl.PROTOCOL_TLSv1)
)
opener = request.build_opener(ssl_context, cookie_handler)
request.install_opener(opener)
The src/you_get/extractors/infoq.py module employs an identical strategy, demonstrating that this is the standard pattern within the codebase for handling TLS version mismatches on a per-site basis.
How SSL Contexts Are Applied
The application of these SSL/TLS configuration options follows a clear hierarchy:
- Default behavior: Uses Python's standard SSL verification with the system's CA bundle and default TLS version
- Global
--insecureflag: Creates unverified contexts viassl.SSLContext()with disabled verification incommon.py - Per-extractor contexts: Build custom
HTTPSHandlerobjects with specificSSLContextprotocol versions, assembled throughrequest.build_opener()and activated viarequest.install_opener()
This architecture allows you-get to maintain secure defaults while providing escape hatches for both global connectivity issues (via the CLI flag) and specific site requirements (via extractor code).
Summary
- The
--insecure(-k) flag globally disables SSL certificate verification by settingverify_mode = ssl.CERT_NONEinsrc/you_get/common.py - Individual extractors can enforce specific TLS versions using custom
SSLContextobjects with explicit protocol selection (TLS 1.0, 1.2, etc.) - Tumblr, NicoVideo, and InfoQ extractors demonstrate per-site TLS configuration via
HTTPSHandlerandbuild_opener()patterns - Default behavior relies on Python's standard certificate verification and TLS negotiation
Frequently Asked Questions
How do I bypass SSL certificate errors when downloading with you-get?
Use the -k or --insecure command-line flag. According to the source code in src/you_get/common.py, this sets a global flag that creates SSL contexts with ssl.CERT_NONE and disabled hostname checking, allowing connections to servers with expired or self-signed certificates.
Can I force a specific TLS version like 1.2 for all downloads?
The command-line interface does not expose a global TLS version selector. However, individual extractors in src/you_get/extractors/ (such as Tumblr) implement site-specific TLS 1.2 enforcement by constructing custom SSLContext objects with ssl.PROTOCOL_TLSv1_2 and installing them via urllib.request.build_opener().
Why does you-get use different SSL configurations for different sites?
Some legacy servers or restrictive CDNs reject modern TLS handshakes and require specific protocol versions (like TLS 1.0 or 1.2). The per-extractor SSL contexts in files like src/you_get/extractors/nicovideo.py override the default negotiation to maintain compatibility without compromising security for other requests.
Is the --insecure flag safe to use?
The --insecure flag disables certificate verification entirely, which protects against connection failures but removes protection against man-in-the-middle attacks. As implemented in src/you_get/common.py, this sets check_hostname = False and verify_mode = ssl.CERT_NONE, so use it only when accessing trusted servers with known certificate issues.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →