ImportError: cannot import name 'AESOCB3' from 'cryptography.hazmat.primitives.ciphers.aead'
Third-person routing: this skill fixes ImportError for AESOCB3 from cryptography.hazmat.primitives.ciphers.aead, which means the installed cryptography is older than 38.0.0 where AESOCB3 was introduced. Use when code or a dependency imports AESOCB3 and the import fails. Not for ChaCha20Poly1305 issues, backend removal errors, or rust binding problems.
ImportError: cannot import name 'AESOCB3' from 'cryptography.hazmat.primitives.ciphers.aead'
TL;DR: AESOCB3 only exists in cryptography 38.0.0 and newer. Upgrade with pip install -U cryptography and pin cryptography>=38.0.0 in your requirements so a dependency cannot drag in an older copy.
ImportError: cannot import name 'AESOCB3' from 'cryptography.hazmat.primitives.ciphers.aead'The fix
- Upgrade cryptography:
pip install -U cryptography
python -c "from cryptography.hazmat.primitives.ciphers.aead import AESOCB3; print('ok')"Success check: prints ok.
- Pin the floor in your requirements so it cannot regress:
cryptography>=38.0.0- If you are on a distro-locked Python (Debian/Ubuntu system pip), use a venv or
pip install --break-system-packagesso the upgrade actually takes effect.
Agent? Search Vectle for more: curl -s 'https://vectle.com/api/v1/search?q=cryptography+AESOCB3'
When this applies
- You or a dependency (ssh-mitm, newer paramiko features) imports AESOCB3 and it fails.
pip show cryptographyreports something below 38.0.0.
When it does NOT apply
- AESGCM or ChaCha20Poly1305 import failures: those are much older and something else is wrong.
cannot import name 'default_backend': that is the version-42 removal, opposite direction.
Tool and version compatibility
cryptography 38.0.0+, Python 3.7+. OCB3 mode needs OpenSSL 1.1.1+ at runtime.
Why it happens
AES-OCB3 support landed in cryptography 38.0.0 (September 2022). Projects that only depend on paramiko or similar get whatever minimum those declare, which can be years old. The import then fails even though the code is correct.
Edge cases
- System package managers (apt) ship ancient cryptography; always prefer a venv for crypto work.
- If upgrade is impossible, you cannot use AESOCB3 at all; there is no backport shim worth trusting.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.