Welcome! Log In Create A New Profile

Advanced

RE: opinions about Session tickets

Arnaud Van der Vorst
April 12, 2016 02:34AM
Good morning,

@Andreas
Thank you for sharing these documents.
I had already read the one from Tim Taubert and had the same concern about
using TLS/SSL Tickets.
Is it a good thing or not?

-----Original Message-----
From: nginx [mailto:nginx-bounces@nginx.org] On Behalf Of A. Schulze
Sent: lundi 11 avril 2016 17:17
To: nginx@nginx.org
Subject: opinions about Session tickets


Maxim Dounin:

> In nginx 1.5.9 the "ssl_session_tickets" directive was added, which
> makes it possible to disable session tickets when needed.

I found these two opinions. They suggest to disable session tickets.

-
https://www.farsightsecurity.com/Blog/20151202-thall-hardening-dh-and-ecc/
-
https://timtaubert.de/blog/2014/11/the-sad-state-of-server-side-tls-session-
resumption-implementations/

what do others think about that?
Andreas


_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx

_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

TLS/SSL Cache Automatic Purge

Arnaud Van der Vorst April 11, 2016 04:42AM

Re: TLS/SSL Cache Automatic Purge

B.R. April 11, 2016 07:26AM

RE: TLS/SSL Cache Automatic Purge

Arnaud Van der Vorst April 11, 2016 08:24AM

Re: TLS/SSL Cache Automatic Purge

Maxim Dounin April 11, 2016 09:32AM

opinions about Session tickets

A. Schulze April 11, 2016 11:18AM

RE: opinions about Session tickets

Arnaud Van der Vorst April 12, 2016 02:34AM

AW: RE: opinions about Session tickets

Lukas Tribus March 28, 2017 07:54PM

RE: opinions about Session tickets

Lukas Tribus April 12, 2016 05:18AM

Re: RE: opinions about Session tickets

alweiss March 28, 2017 04:42PM

Re: TLS/SSL Cache Automatic Purge

B.R. April 11, 2016 04:18PM

RE: TLS/SSL Cache Automatic Purge

Arnaud Van der Vorst April 12, 2016 02:32AM

RE: TLS/SSL Cache Automatic Purge

Lukas Tribus April 12, 2016 05:24AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 263
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready