Repository navigation
TLS 1.3: number session ticket nonces per connection - #11692
Open
julek-wolfssl wants to merge 1 commit into
Open
julek-wolfssl wants to merge 1 commit into
julek-wolfssl wants to merge 1 commit into
Conversation
The server restored the nonce of the ticket a client resumed with into ssl->session->ticketNonce to derive the resumption PSK, and then went on counting from it for the tickets of the new connection. Every resumption in a chain added one, so the 256th resumption from the newest ticket failed with SESSION_TICKET_NONCE_OVERFLOW. A server object reused with wolfSSL_clear() kept counting the same way, as the session of a completed handshake is kept. RFC 8446 Section 4.6.1 only needs the nonce to be unique among the tickets of one connection, and the PSK of a ticket is derived from the resumption master secret of the connection that issued it. Clear the nonce once the PSK is derived, and in wolfSSL_clear() on the server, so that every connection numbers its tickets from 0.
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The focused state resets are correctly guarded and covered by targeted regression tests.
0 open findings
What changed in this PR
Resets TLS 1.3 session-ticket nonces per connection, preventing overflow across chained resumptions and reused server objects.
Changes:
- Clear a resumed ticket’s nonce after PSK derivation.
- Reset server ticket nonce state in
wolfSSL_clear(). - Add regression tests for chained resumptions and server reuse.
| File | Description |
|---|---|
src/tls13.c |
Resets nonce state after resumption PSK derivation. |
src/ssl.c |
Resets server nonce state during connection reuse. |
tests/api/test_tls13.c |
Tests per-connection numbering and server reuse. |
tests/api/test_tls13.h |
Registers the new TLS 1.3 tests. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The server restored the nonce of the ticket a client resumed with into
ssl->session->ticketNonceto derive the resumption PSK, then kept counting from it for the tickets of the new connection. Every resumption in a chain added one, so the 256th resumption from the newest ticket failed withSESSION_TICKET_NONCE_OVERFLOW. A server object reused withwolfSSL_clear()kept counting the same way, because the session of a completed handshake is kept.RFC 8446 Section 4.6.1 only requires the nonce to be unique among the tickets of one connection, and a ticket's PSK is derived from the resumption master secret of the connection that issued it.
wolfSSL_clear()on the server.Every connection now numbers its tickets from 0.