]> Cypherpunks repositories - gostls13.git/commit
crypto/tls: Never resume sessions across different versions.
authorDavid Benjamin <davidben@google.com>
Mon, 15 Feb 2016 16:41:40 +0000 (11:41 -0500)
committerBrad Fitzpatrick <bradfitz@golang.org>
Wed, 18 May 2016 21:20:33 +0000 (21:20 +0000)
commitebbe4f8db76b947663cc535602054c84b01b080d
tree26d4ce6f4ac02577a429cd001ed39d374b063db7
parentd8bd7b24fcc72fb4117f7fc249ceaa79f69d4e00
crypto/tls: Never resume sessions across different versions.

Instead, decline the session and do a full handshake. The semantics of
cross-version resume are unclear, and all major client implementations
treat this as a fatal error. (This doesn't come up very much, mostly if
the client does the browser version fallback without sharding the
session cache.)

See BoringSSL's bdf5e72f50e25f0e45e825c156168766d8442dde and OpenSSL's
9e189b9dc10786c755919e6792e923c584c918a1.

Change-Id: I51ca95ac1691870dd0c148fd967739e2d4f58824
Reviewed-on: https://go-review.googlesource.com/21152
Reviewed-by: Adam Langley <agl@golang.org>
Run-TryBot: Brad Fitzpatrick <bradfitz@golang.org>
TryBot-Result: Gobot Gobot <gobot@golang.org>
src/crypto/tls/handshake_server.go
src/crypto/tls/handshake_server_test.go