@@ -500,6 +500,9 @@ public static void setSessionTicketKeys(long ctx, SessionTicketKey[] keys) {
500500 * Allow to hook {@link CertificateVerifier} into the handshake processing.
501501 * This will call {@code SSL_CTX_set_cert_verify_callback} and so replace the default verification
502502 * callback used by openssl
503+ * <p>
504+ * <strong>Important: This method must only be called before any SSL object was created and used
505+ * that belongs to this context. Failing to do so results in undefined behaviour.</strong>
503506 * @param ctx Server or Client context to use.
504507 * @param verifier the verifier to call during handshake.
505508 */
@@ -509,6 +512,9 @@ public static void setSessionTicketKeys(long ctx, SessionTicketKey[] keys) {
509512 * Allow to hook {@link CertificateRequestedCallback} into the certificate choosing process.
510513 * This will call {@code SSL_CTX_set_client_cert_cb} and so replace the default verification
511514 * callback used by openssl
515+ * <p>
516+ * <strong>Important: This method must only be called before any SSL object was created and used
517+ * that belongs to this context. Failing to do so results in undefined behaviour.</strong>
512518 * @param ctx Server or Client context to use.
513519 * @param callback the callback to call during certificate selection.
514520 * @deprecated use {@link #setCertificateCallback(long, CertificateCallback)}
@@ -520,6 +526,9 @@ public static void setSessionTicketKeys(long ctx, SessionTicketKey[] keys) {
520526 * Allow to hook {@link CertificateCallback} into the certificate choosing process.
521527 * This will call {@code SSL_CTX_set_cert_cb} and so replace the default verification
522528 * callback used by openssl
529+ * <p>
530+ * <strong>Important: This method must only be called before any SSL object was created and used
531+ * that belongs to this context. Failing to do so results in undefined behaviour.</strong>
523532 * @param ctx Server or Client context to use.
524533 * @param callback the callback to call during certificate selection.
525534 */
@@ -529,6 +538,9 @@ public static void setSessionTicketKeys(long ctx, SessionTicketKey[] keys) {
529538 * Allow to hook {@link SniHostNameMatcher} into the sni processing.
530539 * This will call {@code SSL_CTX_set_tlsext_servername_callback} and so replace the default
531540 * callback used by openssl
541+ * <p>
542+ * <strong>Important: This method must only be called before any SSL object was created and used
543+ * that belongs to this context. Failing to do so results in undefined behaviour.</strong>
532544 * @param ctx Server or Client context to use.
533545 * @param matcher the matcher to call during sni hostname matching.
534546 */
@@ -541,6 +553,9 @@ public static void setSessionTicketKeys(long ctx, SessionTicketKey[] keys) {
541553 * <p>
542554 * <strong>Warning:</strong> The log output will contain secret key material, and can be used to decrypt
543555 * TLS sessions! The log output should be handled with the same care given to the private keys.
556+ * <p>
557+ * <strong>Important: This method must only be called before any SSL object was created and used
558+ * that belongs to this context. Failing to do so results in undefined behaviour.</strong>
544559 * @param ctx Server or Client context to use.
545560 * @param callback the callback to call when delivering debug output.
546561 * @return {@code true} if the key-log callback was assigned,
@@ -722,7 +737,9 @@ public static void setPrivateKeyMethod(long ctx, AsyncSSLPrivateKeyMethod method
722737
723738 /**
724739 * Set the {@link SSLSessionCache} that will be used if session caching is enabled.
725- *
740+ * <p>
741+ * <strong>Important: This method must only be called before any SSL object was created and used
742+ * that belongs to this context. Failing to do so results in undefined behaviour.</strong>
726743 * @param ctx context to use.
727744 * @param cache cache to use for the given context.
728745 */
0 commit comments