mirror of
https://github.com/curl/curl.git
synced 2026-08-24 21:43:32 +03:00
lib: TLS session ticket caching reworked
Described in detail in internal doc TLS-SESSIONS.md Main points: - use a new `ssl_peer_key` for cache lookups by connection filters - recognize differences between TLSv1.3 and other tickets * TLSv1.3 tickets are single-use, cache can hold several of them for a peer * TLSv1.2 are reused, keep only a single one per peer - differentiate between ticket BLOB to store (that could be persisted) and object instances - use put/take/return pattern for cache access - remember TLS version, ALPN protocol, time received and lifetime of ticket - auto-expire tickets after their lifetime Closes #15774
This commit is contained in:
parent
e5e2e09a75
commit
fa0ccd9f1f
36 changed files with 1784 additions and 780 deletions
|
|
@ -271,21 +271,7 @@ enum protection_level {
|
|||
|
||||
/* SSL backend-specific data; declared differently by each SSL backend */
|
||||
struct ssl_backend_data;
|
||||
|
||||
typedef enum {
|
||||
CURL_SSL_PEER_DNS,
|
||||
CURL_SSL_PEER_IPV4,
|
||||
CURL_SSL_PEER_IPV6
|
||||
} ssl_peer_type;
|
||||
|
||||
struct ssl_peer {
|
||||
char *hostname; /* hostname for verification */
|
||||
char *dispname; /* display version of hostname */
|
||||
char *sni; /* SNI version of hostname or NULL if not usable */
|
||||
ssl_peer_type type; /* type of the peer information */
|
||||
int port; /* port we are talking to */
|
||||
int transport; /* one of TRNSPRT_* defines */
|
||||
};
|
||||
struct Curl_ssl_scache_entry;
|
||||
|
||||
struct ssl_primary_config {
|
||||
char *CApath; /* certificate dir (does not work on Windows) */
|
||||
|
|
@ -341,24 +327,6 @@ struct ssl_general_config {
|
|||
int ca_cache_timeout; /* Certificate store cache timeout (seconds) */
|
||||
};
|
||||
|
||||
typedef void Curl_ssl_sessionid_dtor(void *sessionid, size_t idsize);
|
||||
|
||||
/* information stored about one single SSL session */
|
||||
struct Curl_ssl_session {
|
||||
char *name; /* hostname for which this ID was used */
|
||||
char *conn_to_host; /* hostname for the connection (may be NULL) */
|
||||
const char *scheme; /* protocol scheme used */
|
||||
char *alpn; /* APLN TLS negotiated protocol string */
|
||||
void *sessionid; /* as returned from the SSL layer */
|
||||
size_t idsize; /* if known, otherwise 0 */
|
||||
Curl_ssl_sessionid_dtor *sessionid_free; /* free `sessionid` callback */
|
||||
long age; /* just a number, the higher the more recent */
|
||||
int remote_port; /* remote port */
|
||||
int conn_to_port; /* remote port for the connection (may be -1) */
|
||||
int transport; /* TCP or QUIC */
|
||||
struct ssl_primary_config ssl_config; /* setup for this session */
|
||||
};
|
||||
|
||||
#ifdef USE_WINDOWS_SSPI
|
||||
#include "curl_sspi.h"
|
||||
#endif
|
||||
|
|
@ -1232,8 +1200,7 @@ struct UrlState {
|
|||
curl_prot_t first_remote_protocol;
|
||||
|
||||
int retrycount; /* number of retries on a new connection */
|
||||
struct Curl_ssl_session *session; /* array of 'max_ssl_sessions' size */
|
||||
long sessionage; /* number of the most recent session */
|
||||
struct Curl_ssl_scache *ssl_scache; /* TLS session pool */
|
||||
int os_errno; /* filled in with errno whenever an error occurs */
|
||||
long followlocation; /* redirect counter */
|
||||
int requests; /* request counter: redirects + authentication retakes */
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue