[prev in list] [next in list] [prev in thread] [next in thread] 

List:       apache-httpd-users
Subject:    [users@httpd] session resumption not possible after graceful restart if tlsv1.3
From:       Dominik Stillhard <Dominik.Stillhard () united-security-providers ! ch>
Date:       2020-02-06 8:15:26
Message-ID: 83CBBB217D00184187EEDA53C1A3E8D6B69CC34F () uspEXCH02 ! u-s-p ! local
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


Hello dear apache users

With TLSv1.2 it is possible to resume a ssl-session after a graceful restar=
t, if a sessioncache is defined vie SSLSessionCache directive.
When I try to do the same with TLSv1.3, a full handshake is performed. With=
out the graceful restart, resumption works correctly.
Tested on apache 2.4.41

More details on stackoverflow:
https://stackoverflow.com/questions/60080365/apaches-sslsessioncache-not-wo=
rking-correctly-with-tlsv1-3-and-graceful-restart

Any Idea what could be the problem? I didn't find a bug report on this...

Kind regards
Dominik

[Attachment #5 (text/html)]

<html xmlns:v="urn:schemas-microsoft-com:vml" \
xmlns:o="urn:schemas-microsoft-com:office:office" \
xmlns:w="urn:schemas-microsoft-com:office:word" \
xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" \
xmlns="http://www.w3.org/TR/REC-html40"> <head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Verdana;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;
	mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
span.E-MailFormatvorlage17
	{mso-style-type:personal-compose;
	font-family:"Verdana",sans-serif;
	color:black;
	font-weight:normal;
	font-style:normal;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;
	mso-fareast-language:EN-US;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 2.0cm 70.85pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="DE-CH" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black">Hello \
dear apache users<o:p></o:p></span></p> <p class="MsoNormal"><span \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black"><o:p>&nbsp;</o:p></span></p>
 <p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black">With \
TLSv1.2 it is possible to resume a ssl-session after a graceful restart, if a \
sessioncache is defined vie SSLSessionCache directive.<o:p></o:p></span></p> <p \
class="MsoNormal"><span lang="EN-US" \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black">When \
I try to do the same with TLSv1.3, a full handshake is performed. Without the \
graceful restart, resumption works correctly.<o:p></o:p></span></p> <p \
class="MsoNormal"><span lang="EN-US" \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black">Tested \
on apache 2.4.41<o:p></o:p></span></p> <p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black"><o:p>&nbsp;</o:p></span></p>
 <p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black">More \
details on stackoverflow:<o:p></o:p></span></p> <p class="MsoNormal"><span \
lang="EN-US" style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black"><a \
href="https://stackoverflow.com/questions/60080365/apaches-sslsessioncache-not-working \
-correctly-with-tlsv1-3-and-graceful-restart">https://stackoverflow.com/questions/6008 \
0365/apaches-sslsessioncache-not-working-correctly-with-tlsv1-3-and-graceful-restart</a><o:p></o:p></span></p>
 <p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black"><o:p>&nbsp;</o:p></span></p>
 <p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black">Any \
Idea what could be the problem? I didn&#8217;t find a bug report on \
this&#8230;<o:p></o:p></span></p> <p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black"><o:p>&nbsp;</o:p></span></p>
 <p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black">Kind \
regards<o:p></o:p></span></p> <p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:black">Dominik
 <o:p></o:p></span></p>
</div>
</body>
</html>


["smime.p7s" (application/pkcs7-signature)]

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic