Skip to content

fix: skip TLS 1.2 resumption on extended_master_secret mismatch - #417

Open
thesinakamali wants to merge 1 commit into
refraction-networking:masterfrom
thesinakamali:fix/tls12-ems-resumption
Open

thesinakamali wants to merge 1 commit into
refraction-networking:masterfrom
thesinakamali:fix/tls12-ems-resumption

Conversation

@thesinakamali

Copy link
Copy Markdown
Contributor

loadSession does not compare the cached session's extended_master_secret state against the ClientHello being sent. A ClientHelloSpec that omits the EMS extension could pair with a cached session established with EMS, and the server then aborts (handshake_server.go already enforces this). Fix by skipping resumption on a mismatch so the connection proceeds with a full handshake using the selected spec.

This requires ApplyPreset to stop leaving hello.Ems at the makeClientHello default of true. It is now cleared when the preset is applied and set again by ExtendedMasterSecretExtension.writeToUConn only when the spec carries the extension, so hello.extendedMasterSecret reflects what is on the wire. This is the same behavior #307 aimed for, and doing it in ApplyPreset rather than in makeClientHelloForApplyPreset keeps it in uTLS-only code, so it isn't affected by future stdlib syncs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant