I’m not sure what “this” refers to (in “This is true” and “this should automatically work correctly”).

My only concern is to avoid giving a false sense of security, so my initial stance was all-or-nothing.  However with the recent trend of incremental improvements to the PyPI ecosystem, I think it’s important to do what we can and keep the momentum, so I’m okay with the commit—I just wanted to make sure that committing half a fix was intentional.  You probably know more about SSL than me and you’re the RM, so let’s ship this. :)
