-
OCSP certificate revocation checks are now off unless you opt in. Set
ocsp_fail_open=Trueorocsp_fail_open=Falseto enable OCSP. The stored default isNone(unset); only an explicitTrue/Falseopts in, so forwardingDEFAULT_CONFIGURATIONas kwargs does not turn OCSP on.disable_ocsp_checks=True(orinsecure_mode=True) always turns OCSP off, including whenocsp_fail_openis also set.disable_ocsp_checks=Falseandinsecure_mode=Falseare the stored defaults and are not an opt-in. Connection attributeocsp_fail_openis no longer a report of whether OCSP is fail-open; it is the stored preference (None= unset,True= fail-open,False= fail-closed). Use_ocsp_mode()/disable_ocsp_checksto see whether checks are actually on.ocsp_response_cache_filenameandocsp_root_certs_dict_lock_timeoutdo not turn OCSP on; if they are set without an OCSP mode parameter they are ignored and a warning is logged. TheSF_OCSP_FAIL_OPENenvironment variable still only switches fail-open vs fail-closed after OCSP is already on. LoginOCSP_MODEtelemetry now reportsDISABLE_OCSP_CHECKSby default. The process-globalFEATURE_OCSP_MODEis updated by each constructed REST client, except that a later default (OCSP off) client does not overwrite a non-default already stored on the process, and a laterFAIL_OPENclient does not overwriteFAIL_CLOSED. -
Fixed external-browser (SSO) authentication to validate the
Originheader on the local callback server, rejecting tokens delivered from unexpected origins. A trailing slash in the origin (e.g.https://account.snowflakecomputing.com/) is now accepted on par with the bare origin, matching JDBC and other driver behaviour. Preconnect probe connections (empty recv) no longer count against the retry budget and no longer abort the login flow. -
Added the
SNOWFLAKE_TLS_CIPHERSenvironment variable to restrict which TLS ciphers the connector offers. It takes a colon-separated list; names beginning withTLS_are applied as TLS 1.3 cipher suites and the remainder as the cipher list for TLS 1.2 and below, so a single variable covers both. Leaving it unset keeps OpenSSL's defaults unchanged, and an unrecognized cipher name is rejected rather than silently ignored. The restriction covers Snowflake API traffic, cloud-storage (stage) transfers, OCSP/CRL fetches and IdP requests. Requests issued by the AWS and Azure SDKs, and asynchronous connections, are not covered — for TLS 1.3 suites specifically they cannot be, because the Python standard library exposes no API for restricting them. -
Raised the minimum
pyOpenSSLrequirement to 25.3.0, the first version providingset_tls13_ciphersuites. This does not narrow the set of installable versions in practice: earlier releases capcryptographybelow 46 and so were already uninstallable alongside the connector's owncryptography>=46.0.5requirement. -
Added the
workload_identity_hostconnection option that overrides the STS host used by AWS Workload Identity Federation, for endpoints the driver cannot derive from the region (such as an interface VPC endpoint). The default STS host is now resolved via botocore so partitions that do not useamazonaws.com(ISO, European Sovereign Cloud, ...) get the correct hostname. A privately routed host cannot be reached by Snowflake on the default GetCallerIdentity path, so a VPC or PrivateLink STS endpoint also requiresworkload_identity_aws_use_outbound_token=True(SNOW-4017192). -
Fixed MD5 computation for Azure clouds (SNOW-4168830).