bneradt opened a new pull request, #13736:
URL: https://github.com/apache/trafficserver/pull/13736

   Since #13677, every certificate context protects its session tickets
   with the global ticket keys. For a client that sends no SNI, the
   certificate is chosen by destination address, so a ticket issued on one
   address now resumes on another address serving a different certificate,
   and the client is never shown that certificate. The per-context random
   keys that #13677 removed were the only thing keeping those tickets
   apart.
   
   This patch derives the ticket keys for a context selected by
   destination address from the global keys and a digest of that context's
   certificate. A ticket from another certificate then fails its HMAC
   check and the client falls back to a full handshake. Servers sharing
   the ticket key file and serving the same certificate derive the same
   keys, so they keep resuming each other's tickets as #13677 intended.
   Contexts not selected by address use the global keys as before.
   
   Fixes: #13735
   
   Co-Authored-By: Claude Opus 5.5 <[email protected]>
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to