Closed Bug 1656429 Opened 6 years ago Closed 6 years ago

RTT estimate used for 0-RTT anti-replay is incorrect for SSL_SendSessionTicket

Categories

(NSS :: Libraries, defect)

defect

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: mt, Assigned: mt)

Details

Attachments

(1 file)

RTT estimation is used to correct for the propagation delay involved in transmitting a session ticket and later having it used for 0-RTT. This helps narrow the window we use for anti-replay.

The way it currently works is that a value is set when the ServerHello is sent, then that is used as a reference point when sending NewSessionTicket. This only works when NewSessionTicket is sent at the end of the handshake. If SSL_SendSessionTicket is sent later, the RTT estimate is massively inflated.

The fix is to finalize the calculation of the estimate during the handshake.

This was never a security problem, but the more time that passes between the
handshake and sending a ticket, the more likely we are to reject 0-RTT.
Eventually, 0-RTT only works if it is delayed in the network by a surprising
amount.

Assignee: nobody → mt
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → FIXED
Target Milestone: --- → 3.56
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: