RTT estimate used for 0-RTT anti-replay is incorrect for SSL_SendSessionTicket
Categories
(NSS :: Libraries, defect)
Tracking
(Not tracked)
People
(Reporter: mt, Assigned: mt)
Details
Attachments
(1 file)
RTT estimation is used to correct for the propagation delay involved in transmitting a session ticket and later having it used for 0-RTT. This helps narrow the window we use for anti-replay.
The way it currently works is that a value is set when the ServerHello is sent, then that is used as a reference point when sending NewSessionTicket. This only works when NewSessionTicket is sent at the end of the handshake. If SSL_SendSessionTicket is sent later, the RTT estimate is massively inflated.
The fix is to finalize the calculation of the estimate during the handshake.
| Assignee | ||
Comment 1•6 years ago
|
||
This was never a security problem, but the more time that passes between the
handshake and sending a ticket, the more likely we are to reject 0-RTT.
Eventually, 0-RTT only works if it is delayed in the network by a surprising
amount.
| Assignee | ||
Updated•6 years ago
|
Comment 2•6 years ago
|
||
Description
•