Welcome! Log In Create A New Profile

Advanced

Re: TLS session resumption (identifier)

March 04, 2016 05:20AM
On 04 Mar 2016, at 12:55, B.R. <reallfqq-nginx@yahoo.fr> wrote:

> On Fri, Mar 4, 2016 at 10:33 AM, Igor Sysoev <igor@sysoev.ru> wrote:
>> But still, advertising something without actually supporting it must lead to cases where sessions reuse is believed to take place without ever happening, harming performance... that was probably happening in versions < 1.5.9.
>
> I do not think that it should harm performance.
>
> ​Oh yes it does​... I am surprised by your stance and I beg to differ.
> Having quite some load from many clients on a web-server delivering content over HTTPS, it relieves a lot of pain to save CPU cycles by avoiding a full handshake.
> When a client browses a website, (s)he will initiate many connections. Beyond the first one (ones with multiplexing?), session reuse kicks in. Repeat that for each client and sum all the saved CPU cycles. Even an improper (non-scientific) benchmark will show you improvement.
>
> Session reuse is part of the effort of optimizing TLS trafic to minimize its overhead. Have a talk about it with the W3C webperf group if you wish, to which Ilya Grigorik (participated at nginxconf 2014) belongs. Have a look at his checklist too.​

Sorry, I meant there is no performance difference between “none” and “off” settings.

As to default value, builtin session cache was by default initially but it turned out that
it leads to memory fragmentation. So the default value has been changed to “off” and
later to “none”.

Of course shared cache is certainly better as default value but there is no good understanding
what default cache size should be used. And now it becomes less important with ticket introduction.


--
Igor Sysoev
http://nginx.com

_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

TLS session resumption (identifier)

B.R. March 03, 2016 06:52AM

Re: TLS session resumption (identifier)

Maxim Dounin March 03, 2016 08:30AM

Re: TLS session resumption (identifier)

B.R. March 03, 2016 10:44AM

Re: TLS session resumption (identifier)

Igor Sysoev March 03, 2016 10:50AM

Re: TLS session resumption (identifier)

B.R. March 04, 2016 04:22AM

Re: TLS session resumption (identifier)

Igor Sysoev March 04, 2016 04:42AM

Re: TLS session resumption (identifier)

B.R. March 04, 2016 04:58AM

Re: TLS session resumption (identifier)

Igor Sysoev March 04, 2016 05:20AM

Re: TLS session resumption (identifier)

B.R. March 04, 2016 05:32AM

Re: TLS session resumption (identifier)

Igor Sysoev March 04, 2016 05:40AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 169
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready