FTP: fix TLS session reuse on the data connection

FTP servers using SSL can be configured to check TLS session reuse on
the DATA connection. They hand out a new session on every CONTROL
connect and require to see the client using exactly that one when
up-/downloading on DATA.

This means:

1. We have to configure the SSL filter on the DATA connection with
   exactly the same peers.

2. We have to remember the SSL session on the CONTROL connection -
   separately from the session cache. The SSL filter on the DATA
   connection then looks for a session at the CONTROL filter and, if
   present, uses that.

Tests:

Enable `require_ssl_reuse` in our pytest setup for vsftpd. This
reproduces the problem reported in #22225 and verifies the fix.

Skip ftp+SSL pytests for rustls, as we have no possibility to reuse
sessions in that backend.

Schannel: we do not run these tests with the backend. I expect it has
similar problems but am not able to verify.

Reported-by: Laurent Sabourin
Fixes #22225
Closes #22246
This commit is contained in:
Stefan Eissing 2026-07-02 12:04:18 +02:00 committed by Daniel Stenberg
parent 0a7ec0ea4d
commit 84ecfb3ecc
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
17 changed files with 485 additions and 190 deletions

View file

@ -217,7 +217,7 @@ class VsFTPD:
f'rsa_cert_file={creds.cert_file}',
f'rsa_private_key_file={creds.pkey_file}',
# require_ssl_reuse=YES means ctrl and data connection need to use the same session
'require_ssl_reuse=NO',
'require_ssl_reuse=YES',
])
if self._ssl_implicit:
conf.extend([