Skip to content

TLS 1.3: number session ticket nonces per connection - #11692

Open
julek-wolfssl wants to merge 1 commit into
wolfSSL:masterfrom
julek-wolfssl:tls13-ticket-nonce-per-connection
Open

julek-wolfssl wants to merge 1 commit into
wolfSSL:masterfrom
julek-wolfssl:tls13-ticket-nonce-per-connection

Conversation

@julek-wolfssl

Copy link
Copy Markdown
Member

The server restored the nonce of the ticket a client resumed with into ssl->session->ticketNonce to derive the resumption PSK, then kept counting from it for the tickets of the new connection. Every resumption in a chain added one, so the 256th resumption from the newest ticket failed with SESSION_TICKET_NONCE_OVERFLOW. A server object reused with wolfSSL_clear() kept counting the same way, because the session of a completed handshake is kept.

RFC 8446 Section 4.6.1 only requires the nonce to be unique among the tickets of one connection, and a ticket's PSK is derived from the resumption master secret of the connection that issued it.

  • Clear the nonce once the PSK is derived.
  • Clear it in wolfSSL_clear() on the server.

Every connection now numbers its tickets from 0.

The server restored the nonce of the ticket a client resumed with into
ssl->session->ticketNonce to derive the resumption PSK, and then went
on counting from it for the tickets of the new connection. Every
resumption in a chain added one, so the 256th resumption from the
newest ticket failed with SESSION_TICKET_NONCE_OVERFLOW. A server object
reused with wolfSSL_clear() kept counting the same way, as the session
of a completed handshake is kept.

RFC 8446 Section 4.6.1 only needs the nonce to be unique among the
tickets of one connection, and the PSK of a ticket is derived from the
resumption master secret of the connection that issued it. Clear the
nonce once the PSK is derived, and in wolfSSL_clear() on the server, so
that every connection numbers its tickets from 0.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused state resets are correctly guarded and covered by targeted regression tests.

0 open findings

What changed in this PR

Resets TLS 1.3 session-ticket nonces per connection, preventing overflow across chained resumptions and reused server objects.

Changes:

  • Clear a resumed ticket’s nonce after PSK derivation.
  • Reset server ticket nonce state in wolfSSL_clear().
  • Add regression tests for chained resumptions and server reuse.
File Description
src/​tls13.c Resets nonce state after resumption PSK derivation.
src/​ssl.c Resets server nonce state during connection reuse.
tests/​api/​test_tls13.c Tests per-connection numbering and server reuse.
tests/​api/​test_tls13.h Registers the new TLS 1.3 tests.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

MemBrowse Memory Report

gcc-arm-cortex-m4-rsa-only

  • FLASH: .text +64 B (+0.0%, 338,544 B / 1,048,576 B, total: 32% used)

gcc-arm-cortex-m4-tls13

  • FLASH: .text +64 B (+0.0%, 247,134 B / 262,144 B, total: 94% used)

gcc-arm-cortex-m7-pq

  • FLASH: .text +64 B (+0.0%, 309,616 B / 1,048,576 B, total: 30% used)

gcc-arm-cortex-m7-tls13

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

TLS 1.3 server fails a client's 256th consecutive ticket resumption with SESSION_TICKET_NONCE_OVERFLOW

3 participants