A client SSLContext can require certificate validation and hostname matching before any socket is opened.
Python TLS client context: require certificate and hostname checks
Operation contract
The client builds its TLS policy once and passes the context to a connection path that supplies the intended server hostname. create_default_context loads a trust policy and enables certificate checks. This local program inspects those settings; it does not perform a handshake, prove a remote certificate valid, or decide whether an arbitrary URL is an allowed destination.
Failure and ownership boundary
Never turn check_hostname off to make an internal service work. Supply the expected DNS name, maintain a deliberate trust store, and test a real endpoint with both accepted and rejected certificates. TLS identity does not replace application authorization or a target allowlist. Trust-store contents and protocol defaults can change with the runtime and system.
Working program
import ssl
client_context = ssl.create_default_context(ssl.Purpose.SERVER_AUTH)
print("hostname_check", client_context.check_hostname)
print("certificate_required", client_context.verify_mode == ssl.CERT_REQUIRED)Output
hostname_check True
certificate_required TrueCosts and limits
Context construction reads trust configuration. Reusing a context avoids repeating that setup, but the program makes no network or throughput claim.
Common Mistakes
- A configured context is not a verified connection.
- A certificate chain without hostname matching does not identify the requested host.
- TLS verification does not authorize a target URL or request body.
