Welcome! Log In Create A New Profile

Advanced

Re: ssl_session_timeout issues

A. Schulze
March 06, 2017 06:42AM
Nomad Worker:

> I read the code of ssl module, the directive ssl_session_timeout seems only
> used for ssl session cache, not for ssl session ticket.
> the document describes the directive as 'Specifies a time during which a
> client may reuse the session parameters.' Is it not exactly?
> Is there any timeout for ssl session ticket ?

or more general: is the usage of ssl session tickets suggested at all?

these two links motivated me to set "ssl_session_tickets off"
- https://www.farsightsecurity.com/Blog/20151202-thall-hardening-dh-and-ecc/
-
https://timtaubert.de/blog/2014/11/the-sad-state-of-server-side-tls-session-resumption-implementations/

What are others opinions?

Andreas


_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

ssl_session_timeout issues

Nomad Worker March 05, 2017 09:58PM

Re: ssl_session_timeout issues

A. Schulze March 06, 2017 06:42AM

Re: ssl_session_timeout issues

Maxim Dounin March 06, 2017 09:04AM

Re: ssl_session_timeout issues

Nomad Worker March 07, 2017 12:49AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 329
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready