Disable all TLS session tickets
authorDaniel Gustafsson <[email protected]>
Fri, 26 Jul 2024 09:09:45 +0000 (11:09 +0200)
committerDaniel Gustafsson <[email protected]>
Fri, 26 Jul 2024 09:09:45 +0000 (11:09 +0200)
commitecbb1cd9b7ec2ef30262708f30397b7d1cdab617
tree33dfef21ba27c3da7da9409580d3524c910570c4
parent33668fbefcc3547cb3641738c449801b07b1ac30
Disable all TLS session tickets

OpenSSL supports two types of session tickets for TLSv1.3, stateless
and stateful. The option we've used only turns off stateless tickets
leaving stateful tickets active. Use the new API introduced in 1.1.1
to disable all types of tickets.

Backpatch to all supported versions.

Reviewed-by: Heikki Linnakangas <[email protected]>
Reported-by: Andres Freund <[email protected]>
Discussion: https://postgr.es/m/20240617173803[email protected]
Backpatch-through: v12
configure
configure.ac
src/backend/libpq/be-secure-openssl.c
src/include/pg_config.h.in