Closed ghost closed 8 years ago
They are included due to a deficiency in python's SSL implementation. The code won't be able to act as a SSL server if you remove the keys. It took me several days to find this. Cryptographically, the keys are ignored.
See: https://github.com/python-git/python/blob/master/Modules/_ssl.c#L291
The SSL keys should not be needed for anonymous mode (aECDH).
And they would be worthless anyway as the private key is publicly available.