Welcome! Log In Create A New Profile

Advanced

RE: TLS/SSL Cache Automatic Purge

Lukas Tribus
April 12, 2016 05:24AM
Hi,


> Just to be perfectly clear: does that mean that session tickets are 
> supported for any version of nginx (including <v1.5.9), provided 
> OpenSSL 0.9.8f is available?

Yes.



> So the directive would be kind of 'intercepting' TLS commands, a man in 
> the middle of client and OpenSSL?

No, the feature [1] sets SSL_OP_NO_TICKET [2], which instructs OpenSSL
to NOT use TLS tickets. By default, OpenSSL uses tickets.



> The only information for ssl_session_timout is “Specifies a time during
> which a client may reuse the session parameters stored in a cache.”
> It does not say anything about purging the TLS/SSL Cache which is my
> concern here.

I don't think the sessions are purged, its probably an LRU.



Lukas


[1] http://hg.nginx.org/nginx/rev/d049b0ea00a3
[2] https://www.openssl.org/docs/manmaster/ssl/SSL_CTX_set_options.html


_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

TLS/SSL Cache Automatic Purge

Arnaud Van der Vorst April 11, 2016 04:42AM

Re: TLS/SSL Cache Automatic Purge

B.R. April 11, 2016 07:26AM

RE: TLS/SSL Cache Automatic Purge

Arnaud Van der Vorst April 11, 2016 08:24AM

Re: TLS/SSL Cache Automatic Purge

Maxim Dounin April 11, 2016 09:32AM

opinions about Session tickets

A. Schulze April 11, 2016 11:18AM

RE: opinions about Session tickets

Arnaud Van der Vorst April 12, 2016 02:34AM

AW: RE: opinions about Session tickets

Lukas Tribus March 28, 2017 07:54PM

RE: opinions about Session tickets

Lukas Tribus April 12, 2016 05:18AM

Re: RE: opinions about Session tickets

alweiss March 28, 2017 04:42PM

Re: TLS/SSL Cache Automatic Purge

B.R. April 11, 2016 04:18PM

RE: TLS/SSL Cache Automatic Purge

Arnaud Van der Vorst April 12, 2016 02:32AM

RE: TLS/SSL Cache Automatic Purge

Lukas Tribus April 12, 2016 05:24AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 160
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready