Skip to content

Commit 731acdf

Browse files
committed
[3.11] gh-156293: Document sni_callback dispatch after a context switch
1 parent 64d5656 commit 731acdf

1 file changed

Lines changed: 11 additions & 0 deletions

File tree

‎Doc/library/ssl.rst‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1748,6 +1748,12 @@ to speed up repeated connections from the same clients.
17481748
:class:`SSLContext` representing a certificate chain that matches the server
17491749
name.
17501750

1751+
If the callback assigns a new context to :attr:`SSLSocket.context`, any
1752+
further ClientHello message on the same connection (for example after a
1753+
TLS 1.3 HelloRetryRequest) is dispatched to the new context's
1754+
*sni_callback*, if it has one; the original callback is not called again
1755+
for that connection.
1756+
17511757
Due to the early negotiation phase of the TLS connection, only limited
17521758
methods and attributes are usable like
17531759
:meth:`SSLSocket.selected_alpn_protocol` and :attr:`SSLSocket.context`.
@@ -1771,6 +1777,11 @@ to speed up repeated connections from the same clients.
17711777

17721778
.. versionadded:: 3.7
17731779

1780+
.. versionchanged:: next
1781+
After the callback assigns a new :attr:`SSLSocket.context`, later
1782+
ClientHello messages on the connection are dispatched to the new
1783+
context's *sni_callback*.
1784+
17741785
.. attribute:: SSLContext.set_servername_callback(server_name_callback)
17751786

17761787
This is a legacy API retained for backwards compatibility. When possible,

0 commit comments

Comments
 (0)