bneradt opened a new pull request, #13463:
URL: https://github.com/apache/trafficserver/pull/13463

   OpenSSL 3.5 can terminate QUIC connections directly, but ATS only had a
   quiche-backed HTTP/3 listener. Operators who want to use the system
   OpenSSL QUIC stack needed a separate downstream backend without changing
   the existing quiche path or origin HTTP/3 scope.
   
   This adds an optional ENABLE_OPENSSL_QUIC backend that uses OpenSSL's
   native QUIC listener and stream APIs for downstream HTTP/3. This keeps
   the backend mutually exclusive with quiche, exposes TS_HAS_OPENSSL_QUIC,
   and shares ATS's existing HTTP/3 stream handling above the transport.
   
   This also installs native-QUIC TLS callbacks for ALPN and SNI
   certificate selection before ATS has a QUIC NetVC to bind. OpenSSL
   native QUIC does not make a selected SSL_CTX certificate active via
   SSL_set_SSL_CTX alone, so this applies the selected cert, key, and chain
   to the connection SSL.
   
   This also broadens client-side HTTP/3 tests to run with either backend,
   keeps H3 streams open across informational responses, and hardens
   transaction cleanup when OpenSSL closes stream state before ATS finishes
   teardown. This caches stream identifiers, declines listener-time QUIC
   tickets until a NetVC is bound, and adds focused H3 lifecycle and
   session-ticket coverage.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to