moonchen commented on issue #13730:
URL: 
https://github.com/apache/trafficserver/issues/13730#issuecomment-5959541251

   Following up from #13729, let’s track both callback resume fixes here. These 
apply to **OpenSSL and BoringSSL**.
   
   - **ClientHello — `ssl_client_hello_callback()`:** Skip completed hooks on 
retry, even after the handshake advances to SNI. This prevents dispatching SNI 
hooks with the ClientHello event.
   - **Certificate — `ssl_cert_callback()`:** Skip completed certificate 
selection and cert hooks. Preserve the plugin-selected certificate and finish 
any remaining CA and session-ticket setup. This also prevents dispatching 
verify-client hooks with the cert event.
   
   Make these callbacks safe to retry: resume from the saved state, skip 
completed hooks, and finish any remaining finalization.
   
   Regression tests should cover:
   
   - Delayed ClientHello hooks followed by delayed cert hooks.
   - Correct hook event IDs.
   - Switching certificate contexts during a cert-hook pause and preserving the 
plugin-selected certificate after resuming.
   - No verify-client hook invocation when client authentication is disabled.
   - Both backends, with TLS 1.2 and TLS 1.3.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to