Yeah, I was surprised by that part until:
"We must also specify the expected peer name on the presented certificate with the `CN_match` option, it will not be inferred from the URL and if it is not specified, the name on the certificate will not be validated."
WTF? Who ever got the idea that this is something that can ever hit production?