backports.ssl_match_hostname
The ssl.match_hostname() function from Python 3.5
Decision gist · record as of 2026-08-14
No. This package is abandoned (last release 2019-01-12) and unnecessary for any modern Python project. Python 3.2+ includes match_hostname() in the standard library; Python 2.x is end-of-life. Install only if maintaining legacy Python 2.x code that cannot be upgraded—otherwise use the built-in ssl.match_hostname().AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Only needed for Python versions earlier than 3.2; modern Python includes match_hostname() in the standard library ssl module.
- The package is abandoned as of 2019-01-12 and has not been updated in 2771 days.
- Modern Python versions (3.2+) include match_hostname() in the standard library, making this backport unnecessary for current projects.
License · maintenance · safety
permissive license (permissive) — Licensed under the Python Software Foundation License (permissive), which poses no restrictions on use or redistribution.
last release 2019-01-12 (2771 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 642,635 downloads/mo, #5,611 on PyPI
Alternatives
Verify before relying
from backports.ssl_match_hostname import match_hostname, CertificateError
import ssl
sslsock = ssl.wrap_socket(sock, ssl_version=ssl.PROTOCOL_SSLv23,
cert_reqs=ssl.CERT_REQUIRED, ca_certs=...)
try:
match_hostname(sslsock.getpeercert(), hostname)
except CertificateError:
pass- Whether this package is still maintained or if it has been formally deprecated in favor of the standard library.
- Whether any security patches have been applied since the last release in 2019.
What it is and what it does
This package backports the ssl.match_hostname() function from Python 3.7 to earlier Python versions. It implements RFC 2818 (and later RFC 6125) compliant hostname matching for SSL/TLS certificates, ensuring that the hostname in a server's certificate matches the hostname you are connecting to—a critical security check for encrypted connections.
The function was introduced in Python 3.2 and has been part of the standard library ever since. This backport was designed for projects supporting older Python versions that lacked the function. However, the package has been abandoned since 2019 and is now obsolete for any project running Python 3.2 or later, which includes all modern Python versions.
Use it for
- Validating SSL certificates in legacy Python 2.x applications that need hostname verification before Python 3.2 was available.
- Ensuring secure HTTPS connections in older Python codebases by checking certificate hostnames match the target server.
- Porting Python 3.x code to run on Python 2.4–2.7 while maintaining SSL security checks.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
This package is abandoned (last release 2019-01-12) and unnecessary for any modern Python project. Python 3.2+ includes match_hostname() in the standard library; Python 2.x is end-of-life. Install only if maintaining legacy Python 2.x code that cannot be upgraded—otherwise use the built-in ssl.match_hostname().
Install
backports-ssl-match-hostname on PyPI
Before you install
The package is abandoned as of 2019-01-12 and has not been updated in 2771 days. Modern Python versions (3.2+) include match_hostname() in the standard library, making this backport unnecessary for current projects. High install friction due to its age and obsolescence.
Only needed for Python versions earlier than 3.2; modern Python includes match_hostname() in the standard library ssl module.
License in practice
Licensed under the Python Software Foundation License (permissive), which poses no restrictions on use or redistribution.
Quickstart
from backports.ssl_match_hostname import match_hostname, CertificateError
import ssl
sslsock = ssl.wrap_socket(sock, ssl_version=ssl.PROTOCOL_SSLv23,
cert_reqs=ssl.CERT_REQUIRED, ca_certs=...)
try:
match_hostname(sslsock.getpeercert(), hostname)
except CertificateError:
pass
Verify before relying
- Whether this package is still maintained or if it has been formally deprecated in favor of the standard library.
- Whether any security patches have been applied since the last release in 2019.
Package facts
| License | permissive license permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Abandoned 2,771 days since the last release |
| First released | |
| Downloads | 642,635 / month, #5,611 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableLicense :: OSI Approved :: Python Software Foundation LicenseProgramming Language :: Python :: 2.4Programming Language :: Python :: 2.5Programming Language :: Python :: 2.6Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.0Programming Language :: Python :: 3.1Programming Language :: Python :: 3.2Programming Language :: Python :: 3.3Programming Language :: Python :: 3.4Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Topic :: Security :: Cryptography |
Evidence: backports.ssl_match_hostname-3.7.0.1.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “ssl certificate hostname validation”
- backports.ssl_match_hostnameProvides the ssl.match_hostname() function for validating that a…
- service-identityVerifies that cryptography or pyOpenSSL certificates are valid for a…
- idna_sslPatches Python's ssl.match_hostname to support Unicode (IDNA) domain…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also idna_ssl · service-identity · backports.ssl · ipaddress · secure-smtplib · hstspreload · fqdn · python-certifi-win32 · pip-system-certs