Skip to content

Commit 5ee05a9

Browse files
committed
[3.10] gh-156293: Document sni_callback dispatch after a context switch
1 parent 7ab129e commit 5ee05a9

1 file changed

Lines changed: 11 additions & 0 deletions

File tree

‎Doc/library/ssl.rst‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1750,6 +1750,12 @@ to speed up repeated connections from the same clients.
17501750
:class:`SSLContext` representing a certificate chain that matches the server
17511751
name.
17521752

1753+
If the callback assigns a new context to :attr:`SSLSocket.context`, any
1754+
further ClientHello message on the same connection (for example after a
1755+
TLS 1.3 HelloRetryRequest) is dispatched to the new context's
1756+
*sni_callback*, if it has one; the original callback is not called again
1757+
for that connection.
1758+
17531759
Due to the early negotiation phase of the TLS connection, only limited
17541760
methods and attributes are usable like
17551761
:meth:`SSLSocket.selected_alpn_protocol` and :attr:`SSLSocket.context`.
@@ -1773,6 +1779,11 @@ to speed up repeated connections from the same clients.
17731779

17741780
.. versionadded:: 3.7
17751781

1782+
.. versionchanged:: next
1783+
After the callback assigns a new :attr:`SSLSocket.context`, later
1784+
ClientHello messages on the connection are dispatched to the new
1785+
context's *sni_callback*.
1786+
17761787
.. attribute:: SSLContext.set_servername_callback(server_name_callback)
17771788

17781789
This is a legacy API retained for backwards compatibility. When possible,

0 commit comments

Comments
 (0)