bneradt opened a new pull request, #13736: URL: https://github.com/apache/trafficserver/pull/13736
Since #13677, every certificate context protects its session tickets with the global ticket keys. For a client that sends no SNI, the certificate is chosen by destination address, so a ticket issued on one address now resumes on another address serving a different certificate, and the client is never shown that certificate. The per-context random keys that #13677 removed were the only thing keeping those tickets apart. This patch derives the ticket keys for a context selected by destination address from the global keys and a digest of that context's certificate. A ticket from another certificate then fails its HMAC check and the client falls back to a full handshake. Servers sharing the ticket key file and serving the same certificate derive the same keys, so they keep resuming each other's tickets as #13677 intended. Contexts not selected by address use the global keys as before. Fixes: #13735 Co-Authored-By: Claude Opus 5.5 <[email protected]> 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
