extension) and force to use stateful session resumption. Stateless
session resumption is more expensive in CPU usage. This option is also
available on global statement "ssl-default-bind-options".
+ The TLS ticket mechanism is only used up to TLS 1.2 and it is prone to
+ man-in-the-middle attacks. You should consider to disable them for
+ security reasons. TLS 1.3 implements more secure methods for session
+ resumption.
no-tlsv10
This setting is only available when support for OpenSSL was built in. It
extension) and force to use stateful session resumption. Stateless
session resumption is more expensive in CPU usage for servers. This option
is also available on global statement "ssl-default-server-options".
+ The TLS ticket mechanism is only used up to TLS 1.2 and it is prone to
+ man-in-the-middle attacks. You should consider to disable them for
+ security reasons. TLS 1.3 implements more secure methods for session
+ resumption.
See also "tls-tickets".
no-tlsv10