Skip to main content

The Secure Sockets layer is only actually secure if you check the hostname in the certificate returned by the server to which you are connecting, and verify that it matches to hostname that you are trying to reach.

But the matching logic, defined in RFC2818, can be a bit tricky to implement on your own. So the ssl package in the Standard Library of Python 3.2 now includes a match_hostname() function for performing this check instead of requiring every application to implement the check separately.

This backport brings match_hostname() to users of earlier versions of Python. Simply make this distribution a dependency of your package, and then use it like this:

from backports.ssl_match_hostname import match_hostname, CertificateError
...
sslsock = ssl.wrap_socket(sock, ssl_version=ssl.PROTOCOL_SSLv3,
                          cert_reqs=ssl.CERT_REQUIRED, ca_certs=...)
try:
    match_hostname(sslsock.getpeercert(), hostname)
except CertificateError, ce:
    ...

Note that the ssl module is only included in the Standard Library for Python 2.6 and later; users of Python 2.5 or earlier versions will also need to install the ssl distribution from the Python Package Index to use code like that shown above.

Brandon Craig Rhodes is merely the packager of this distribution; the actual code inside comes verbatim from Python 3.4a1.

Metadata

Release files for backports.ssl_match_hostname 3.4.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for backports.ssl_match_hostname 3.4.0.1
File Size Uploaded
backports.ssl_match_hostname-3.4.0.1.tar.gz 9.4 kB Details

Release files / backports.ssl_match_hostname-3.4.0.1.tar.gz

Download URL backports.ssl_match_hostname-3.4.0.1.tar.gz
Size 9.4 kB
Tags Source
SHA-256 checksum
How to use checksums
8ae5c577c12a39cc403444db7769458a784382a5f8ce07190297387df2255c41
BLAKE2b-256 checksum
How to use checksums
b05fb718c15078d9c873bc3b0630a925f572535623cb0fcdc2ba8565f0d825df
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

3.7.0.1

1 release file

3.5.0.1

1 release file

3.4.0.2

1 release file

This release

3.4.0.1 This release

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page