Ensure that a resumed session properly handles client auth. Clear session ticket resumption state in wolfSSL_clear. - #11600
Open
kareem-wolfssl wants to merge 8 commits into
Open
kareem-wolfssl wants to merge 8 commits into
kareem-wolfssl wants to merge 8 commits into
Conversation
kareem-wolfssl
requested review from
julek-wolfssl
and
a balanced review from Copilot
September 29, 2026 23:53
|
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The changes introduce an optional-build compilation failure, a callback-backed authentication bypass, and an unversioned persisted-cache layout change.
Review effort: Balanced
Findings: 2
Open (4)
What changed in this PR
Adds client-authentication awareness to resumed sessions and clears stale ticket state during wolfSSL_clear().
Changes:
- Persists client-auth status in sessions and tickets.
- Rejects resumptions that cannot satisfy mandatory client authentication.
- Adds TLS 1.2 resumption and reset tests.
| File | Description |
|---|---|
wolfssl/internal.h |
Adds ticket flags and session authentication state. |
src/internal.c |
Enforces client authentication during TLS 1.2 resumption. |
src/tls13.c |
Enforces authentication for TLS 1.3 ticket PSKs. |
src/ssl.c |
Clears stale ticket and alternate-session state. |
src/ssl_sess.c |
Serializes and populates authentication state. |
tests/api/test_tls.c |
Adds TLS 1.2 resumption and reuse tests. |
tests/api/test_tls.h |
Registers new TLS tests. |
tests/api.c |
Tests session serialization compatibility. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
kareem-wolfssl
force-pushed
the
zd22516
branch
from
September 30, 2026 00:10
b2fffb7 to
9b72742
Compare
julek-wolfssl
requested changes
Sep 30, 2026
julek-wolfssl
left a comment
Member
There was a problem hiding this comment.
It looks correct but the comments are getting too verbose. Cut them down.
kareem-wolfssl
force-pushed
the
zd22516
branch
2 times, most recently
from
September 30, 2026 21:03
54a86f2 to
3d38cef
Compare
Thanks to ByteRay Ltd for the report.
Thanks to ByteRay Ltd for the report.
Also clear peerAuthOk in wolfSSL_Clear Bump up WOLFSSL_CACHE_VERSION Add TLS 1.3 tests Add TLS 1.2 test for clearing peerAuthOk
…hecks mutual auth as well. Reset more fields in wolfSSL_Clear to ensure a full reset. Add a test to ensure wolfSSL_Clear fully clears after a connection. Add a test for resuming in TLS 1.2 with mutual auth, and a test for resuming with PHA in TLS 1.3. Minimize comments.
kareem-wolfssl
force-pushed
the
zd22516
branch
from
October 1, 2026 18:15
d312ca7 to
9edcb65
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Description
Partially fixes zd#22516
Testing
Built in tests, provided reproducers, added tests
Checklist