Commit e4ec899
committed
ssl: issue TLS session tickets for server-side sockets
A server-side SSLSocket did a full handshake for every connection. Browsers
open several connections per page, and on a small MCU with an RSA-2048
certificate each handshake costs ~1.3 s of CPU (ESP32-C6), so pages stalled
and speculative connections were abandoned.
Configure mbedTLS session tickets (AES-256-GCM via PSA, 24 h lifetime, one
process-wide key) on server-side contexts when MBEDTLS_SSL_SESSION_TICKETS and
MBEDTLS_SSL_TICKET_C are available (ESP-IDF enables them by default), so
returning clients resume with an abbreviated handshake and no public-key
operation. Client-side behaviour is unchanged.1 parent 58e036f commit e4ec899
1 file changed
Lines changed: 18 additions & 0 deletions
File tree
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| 24 | + | |
24 | 25 | | |
25 | 26 | | |
26 | 27 | | |
| |||
327 | 328 | | |
328 | 329 | | |
329 | 330 | | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
330 | 348 | | |
331 | 349 | | |
332 | 350 | | |
| |||
0 commit comments