]> git.ipfire.org Git - thirdparty/Python/cpython.git/commitdiff
gh-72507: Document that imaplib does not verify TLS certificates by default (GH-152778)
authorSerhiy Storchaka <storchaka@gmail.com>
Thu, 2 Jul 2026 07:19:11 +0000 (10:19 +0300)
committerGitHub <noreply@github.com>
Thu, 2 Jul 2026 07:19:11 +0000 (10:19 +0300)
IMAP4_SSL() and IMAP4.starttls() do not verify the server certificate or
hostname unless a suitable ssl_context is passed.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Doc/library/imaplib.rst

index 01de1bc393c5bb2d66455d96bbf00d960f16087f..4a714652ecf5d203a1ec417e555e51e7d32d3ae7 100644 (file)
@@ -89,6 +89,13 @@ There's also a subclass for secure connections:
    (potentially long-lived) structure.  Please read :ref:`ssl-security` for
    best practices.
 
+   .. note::
+
+      With the default *ssl_context*, the connection is encrypted but the
+      server certificate and hostname are not verified.
+      To verify them, pass a context created by
+      :func:`ssl.create_default_context`.
+
    The optional *timeout* parameter specifies a timeout in seconds for the
    connection attempt. If timeout is not given or is ``None``, the global default
    socket timeout is used.
@@ -586,6 +593,13 @@ An :class:`IMAP4` instance has the following methods:
    encryption on the IMAP connection.  Please read :ref:`ssl-security` for
    best practices.
 
+   .. note::
+
+      With the default *ssl_context*, the connection is encrypted but the
+      server certificate and hostname are not verified.
+      To verify them, pass a context created by
+      :func:`ssl.create_default_context`.
+
    .. versionadded:: 3.2
 
    .. versionchanged:: 3.4