From: Serhiy Storchaka Date: Thu, 2 Jul 2026 07:19:11 +0000 (+0300) Subject: gh-72507: Document that imaplib does not verify TLS certificates by default (GH-152778) X-Git-Url: http://git.ipfire.org/gitweb/index.cgi?a=commitdiff_plain;h=f3bf8abb8c0f4cb20bed3dc7d98eca4a2d668709;p=thirdparty%2FPython%2Fcpython.git gh-72507: Document that imaplib does not verify TLS certificates by default (GH-152778) IMAP4_SSL() and IMAP4.starttls() do not verify the server certificate or hostname unless a suitable ssl_context is passed. Co-authored-by: Claude Opus 4.8 (1M context) --- diff --git a/Doc/library/imaplib.rst b/Doc/library/imaplib.rst index 01de1bc393c5..4a714652ecf5 100644 --- a/Doc/library/imaplib.rst +++ b/Doc/library/imaplib.rst @@ -89,6 +89,13 @@ There's also a subclass for secure connections: (potentially long-lived) structure. Please read :ref:`ssl-security` for best practices. + .. note:: + + With the default *ssl_context*, the connection is encrypted but the + server certificate and hostname are not verified. + To verify them, pass a context created by + :func:`ssl.create_default_context`. + The optional *timeout* parameter specifies a timeout in seconds for the connection attempt. If timeout is not given or is ``None``, the global default socket timeout is used. @@ -586,6 +593,13 @@ An :class:`IMAP4` instance has the following methods: encryption on the IMAP connection. Please read :ref:`ssl-security` for best practices. + .. note:: + + With the default *ssl_context*, the connection is encrypted but the + server certificate and hostname are not verified. + To verify them, pass a context created by + :func:`ssl.create_default_context`. + .. versionadded:: 3.2 .. versionchanged:: 3.4