]> git.ipfire.org Git - thirdparty/openssl.git/commit
ticket_lifetime_hint may exceed 1 week in TLSv1.3
authorTodd Short <todd.short@me.com>
Wed, 23 Mar 2022 22:55:10 +0000 (18:55 -0400)
committerTodd Short <todd.short@me.com>
Fri, 25 Mar 2022 17:24:05 +0000 (13:24 -0400)
commit79dbd85fe27ebabc278417af64ab8e3eb43d2d40
treeebcf14a503316825bfbe12f3a971c00b204e7204
parent04a768fc5968fa463cf9624a67accdef35bce0e4
ticket_lifetime_hint may exceed 1 week in TLSv1.3

For TLSv1.3, limit ticket lifetime hint to 1 week per RFC8446

Fixes #17948

Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Tim Hudson <tjh@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/17952)

(cherry picked from commit 0089cc7f9d42f6e39872161199fb8b6a99da2492)
doc/man3/SSL_CTX_set_timeout.pod
ssl/statem/statem_srvr.c
test/sslapitest.c