$npx skillfedfor your agent

backports.ssl_match_hostname

The ssl.match_hostname() function from Python 3.5

SkipPyPI CryptographyReleased Jan 2019642.6K downloads / mopermissive licenseSource build

Decision gist · record as of 2026-08-14

sdist only — backports.ssl_match_hostname-3.7.0.1.tar.gz · builds from source
v3.7.0.1 · released 2019-01-12

No. This package is abandoned (last release 2019-01-12) and unnecessary for any modern Python project. Python 3.2+ includes match_hostname() in the standard library; Python 2.x is end-of-life. Install only if maintaining legacy Python 2.x code that cannot be upgraded—otherwise use the built-in ssl.match_hostname().AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Only needed for Python versions earlier than 3.2; modern Python includes match_hostname() in the standard library ssl module.
  • The package is abandoned as of 2019-01-12 and has not been updated in 2771 days.
  • Modern Python versions (3.2+) include match_hostname() in the standard library, making this backport unnecessary for current projects.

License · maintenance · safety

permissive license (permissive) — Licensed under the Python Software Foundation License (permissive), which poses no restrictions on use or redistribution.

last release 2019-01-12 (2771 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 642,635 downloads/mo, #5,611 on PyPI

Verify before relying

from backports.ssl_match_hostname import match_hostname, CertificateError
import ssl

sslsock = ssl.wrap_socket(sock, ssl_version=ssl.PROTOCOL_SSLv23,
                          cert_reqs=ssl.CERT_REQUIRED, ca_certs=...)
try:
    match_hostname(sslsock.getpeercert(), hostname)
except CertificateError:
    pass
  • Whether this package is still maintained or if it has been formally deprecated in favor of the standard library.
  • Whether any security patches have been applied since the last release in 2019.
Same gist for agents: .md · .json

What it is and what it does

This package backports the ssl.match_hostname() function from Python 3.7 to earlier Python versions. It implements RFC 2818 (and later RFC 6125) compliant hostname matching for SSL/TLS certificates, ensuring that the hostname in a server's certificate matches the hostname you are connecting to—a critical security check for encrypted connections.

The function was introduced in Python 3.2 and has been part of the standard library ever since. This backport was designed for projects supporting older Python versions that lacked the function. However, the package has been abandoned since 2019 and is now obsolete for any project running Python 3.2 or later, which includes all modern Python versions.

Use it for

  • Validating SSL certificates in legacy Python 2.x applications that need hostname verification before Python 3.2 was available.
  • Ensuring secure HTTPS connections in older Python codebases by checking certificate hostnames match the target server.
  • Porting Python 3.x code to run on Python 2.4–2.7 while maintaining SSL security checks.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No.

This package is abandoned (last release 2019-01-12) and unnecessary for any modern Python project. Python 3.2+ includes match_hostname() in the standard library; Python 2.x is end-of-life. Install only if maintaining legacy Python 2.x code that cannot be upgraded—otherwise use the built-in ssl.match_hostname().

Install

backports-ssl-match-hostname on PyPI

Before you install

The package is abandoned as of 2019-01-12 and has not been updated in 2771 days. Modern Python versions (3.2+) include match_hostname() in the standard library, making this backport unnecessary for current projects. High install friction due to its age and obsolescence.

Only needed for Python versions earlier than 3.2; modern Python includes match_hostname() in the standard library ssl module.

License in practice

Licensed under the Python Software Foundation License (permissive), which poses no restrictions on use or redistribution.

Quickstart

from backports.ssl_match_hostname import match_hostname, CertificateError
import ssl

sslsock = ssl.wrap_socket(sock, ssl_version=ssl.PROTOCOL_SSLv23,
                          cert_reqs=ssl.CERT_REQUIRED, ca_certs=...)
try:
    match_hostname(sslsock.getpeercert(), hostname)
except CertificateError:
    pass

Verify before relying

  • Whether this package is still maintained or if it has been formally deprecated in favor of the standard library.
  • Whether any security patches have been applied since the last release in 2019.

Package facts

Licensepermissive license permissive
Python supportNot specified
Install frictionHigh. Source build required
Runtime dependenciesNone
MaintenanceAbandoned 2,771 days since the last release
First released
Downloads642,635 / month, #5,611 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableLicense :: OSI Approved :: Python Software Foundation LicenseProgramming Language :: Python :: 2.4Programming Language :: Python :: 2.5Programming Language :: Python :: 2.6Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.0Programming Language :: Python :: 3.1Programming Language :: Python :: 3.2Programming Language :: Python :: 3.3Programming Language :: Python :: 3.4Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Topic :: Security :: Cryptography

Evidence: backports.ssl_match_hostname-3.7.0.1.tar.gz

Tags

Capabilities
ssl certificate hostname validationmatch_hostname backportssl certificate verificationhostname matching sslpython ssl certificate checkrfc 2818 hostname matching
Topics
legacy-pythonssl-tlsdeprecated

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ssl certificate hostname validation”

  • backports.ssl_match_hostnameProvides the ssl.match_hostname() function for validating that a…
  • service-identityVerifies that cryptography or pyOpenSSL certificates are valid for a…
  • idna_sslPatches Python's ssl.match_hostname to support Unicode (IDNA) domain…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also idna_ssl · service-identity · backports.ssl · ipaddress · secure-smtplib · hstspreload · fqdn · python-certifi-win32 · pip-system-certs