ImportError: cannot import name 'asn1' from 'cryptography.hazmat.bindings._rust'
Third-person routing: this skill fixes the cryptography error cannot import name 'asn1' from 'cryptography.hazmat.bindings._rust', which means the installed package mixes stub .pyi files with a missing or broken native _rust extension. Use when the traceback ends in cryptography.hazmat.bindings._rust. Not for default_backend removal, OpenSSL symbol errors, or pure-Python usage.
ImportError: cannot import name 'asn1' from 'cryptography.hazmat.bindings._rust'
TL;DR: your cryptography install is half-broken. The pure-Python stubs (.pyi files) are there but the compiled native extension (_rust.abi3.so) is missing or mismatched. Fix it with a clean reinstall: pip uninstall cryptography -y then pip install --no-cache-dir cryptography.
ImportError: cannot import name 'asn1' from 'cryptography.hazmat.bindings._rust'The fix
- Confirm the native extension is missing:
python -c "import cryptography.hazmat.bindings._rust, os; print(os.path.dirname(cryptography.hazmat.bindings._rust.__file__))"
ls [that-dir] | grep -i "rust.*\.so"Success check: you see only .pyi stub files and no _rust.abi3.so. That confirms the diagnosis.
- Clean reinstall:
pip uninstall -y cryptography
pip install --no-cache-dir cryptography- Verify:
python -c "from cryptography.hazmat.bindings._rust import asn1; print('ok')"Expected output: ok.
Agent? Search Vectle for more: curl -s 'https://vectle.com/api/v1/search?q=cryptography+asn1+_rust'
When this applies
- Traceback goes through
cryptography/hazmat/primitives/...down tofrom cryptography.hazmat.bindings._rust import asn1. - The failing import is triggered by paramiko, pyOpenSSL, or anything importing cryptography.
When it does NOT apply
cannot import name 'default_backend': version-removal issue, different fix.undefined symbol: SSL_...ordlopenfailures: OpenSSL mismatch, different fix.
Tool and version compatibility
cryptography 37+ (rust-backed), Python 3.7+, any OS. Most common on Linux systems with mixed distro/pip installs.
Why it happens
Since 37.0 cryptography ships Rust code compiled into _rust.abi3.so. A partial upgrade, a copied site-packages, or an interrupted pip install can leave the Python stubs without the compiled half. The .pyi files satisfy nothing at runtime, so the first real import fails.
Edge cases
- If the reinstall still fails, check for a second cryptography copy on sys.path (distro package vs pip):
python -c "import cryptography; print(cryptography.__file__)". - Conda users: prefer
conda install -c conda-forge cryptographyover mixing pip and conda. - Never copy site-packages between machines; always reinstall.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.