Would your TLS client have caught the impostor?

Something on the network answers when a client dials a server address. It hands over a certificate. The handshake completes — real crypto, real session key, green padlock. The lock icon can't tell you who you're actually talking to. Only checking whether someone you already trust signed that certificate can.

What actually gets computed when the handshake runs:

Client A — validation off (CERT_NONE, check_hostname=False)

no signature math ever runs — accepts whoever answered

Client B — validation on (loads the CA, keeps hostname checking)

check = signature^e mod n, using only the CA's public key it already trusts