@@ -1859,6 +1859,12 @@ to speed up repeated connections from the same clients.
18591859 :class: `SSLContext ` representing a certificate chain that matches the server
18601860 name.
18611861
1862+ If the callback assigns a new context to :attr: `SSLSocket.context `, any
1863+ further ClientHello message on the same connection (for example after a
1864+ TLS 1.3 HelloRetryRequest) is dispatched to the new context's
1865+ *sni_callback *, if it has one; the original callback is not called again
1866+ for that connection.
1867+
18621868 Due to the early negotiation phase of the TLS connection, only limited
18631869 methods and attributes are usable like
18641870 :meth: `SSLSocket.selected_alpn_protocol ` and :attr: `SSLSocket.context `.
@@ -1883,6 +1889,11 @@ to speed up repeated connections from the same clients.
18831889
18841890 .. versionadded :: 3.7
18851891
1892+ .. versionchanged :: next
1893+ After the callback assigns a new :attr: `SSLSocket.context `, later
1894+ ClientHello messages on the connection are dispatched to the new
1895+ context's *sni_callback *.
1896+
18861897.. method :: SSLContext.set_servername_callback(server_name_callback)
18871898
18881899 This is a legacy API retained for backwards compatibility. When possible,
@@ -2004,7 +2015,11 @@ to speed up repeated connections from the same clients.
20042015 outgoing BIO.
20052016
20062017 The *server_side *, *server_hostname * and *session * parameters have the
2007- same meaning as in :meth: `SSLContext.wrap_socket `.
2018+ same meaning as in :meth: `SSLContext.wrap_socket `, and are validated in
2019+ the same way: in particular a :exc: `ValueError ` is raised when
2020+ :attr: `~SSLContext.check_hostname ` is enabled but no *server_hostname * is
2021+ given, since there would be no name to match the peer's certificate
2022+ against.
20082023
20092024 .. versionchanged :: 3.6
20102025 *session * argument was added.
@@ -2013,6 +2028,13 @@ to speed up repeated connections from the same clients.
20132028 The method returns an instance of :attr: `SSLContext.sslobject_class `
20142029 instead of hard-coded :class: `SSLObject `.
20152030
2031+ .. versionchanged :: next
2032+ The *server_side *, *server_hostname * and *session * parameters are now
2033+ validated as :meth: `SSLContext.wrap_socket ` validates them. Previously
2034+ a context with :attr: `~SSLContext.check_hostname ` enabled and no
2035+ *server_hostname * was accepted, and verified the certificate chain but
2036+ never the peer's identity.
2037+
20162038.. attribute :: SSLContext.sslobject_class
20172039
20182040 The return type of :meth: `SSLContext.wrap_bio `, defaults to
0 commit comments