Skip to content

Commit e4ec899

Browse files
committed
ssl: issue TLS session tickets for server-side sockets
A server-side SSLSocket did a full handshake for every connection. Browsers open several connections per page, and on a small MCU with an RSA-2048 certificate each handshake costs ~1.3 s of CPU (ESP32-C6), so pages stalled and speculative connections were abandoned. Configure mbedTLS session tickets (AES-256-GCM via PSA, 24 h lifetime, one process-wide key) on server-side contexts when MBEDTLS_SSL_SESSION_TICKETS and MBEDTLS_SSL_TICKET_C are available (ESP-IDF enables them by default), so returning clients resume with an abbreviated handshake and no public-key operation. Client-side behaviour is unchanged.
1 parent 58e036f commit e4ec899

1 file changed

Lines changed: 18 additions & 0 deletions

File tree

‎shared-module/ssl/SSLSocket.c‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@
2121
#include "shared-bindings/socketpool/enum.h"
2222

2323
#include "mbedtls/version.h"
24+
#include "mbedtls/ssl_ticket.h"
2425

2526
#define MP_STREAM_POLL_RDWR (MP_STREAM_POLL_RD | MP_STREAM_POLL_WR)
2627

@@ -327,6 +328,23 @@ ssl_sslsocket_obj_t *common_hal_ssl_sslcontext_wrap_socket(ssl_sslcontext_obj_t
327328
goto cleanup;
328329
}
329330
}
331+
#if defined(MBEDTLS_SSL_SESSION_TICKETS) && defined(MBEDTLS_SSL_TICKET_C)
332+
if (server_side) {
333+
// Session tickets let a returning client resume without the (expensive) public-key
334+
// handshake. One process-wide ticket key, rotated by lifetime; nothing to persist.
335+
static mbedtls_ssl_ticket_context ticket_ctx;
336+
static bool ticket_ready = false;
337+
if (!ticket_ready) {
338+
mbedtls_ssl_ticket_init(&ticket_ctx);
339+
if (mbedtls_ssl_ticket_setup(&ticket_ctx, PSA_ALG_GCM, PSA_KEY_TYPE_AES, 256, 86400) == 0) {
340+
ticket_ready = true;
341+
}
342+
}
343+
if (ticket_ready) {
344+
mbedtls_ssl_conf_session_tickets_cb(&o->conf, mbedtls_ssl_ticket_write, mbedtls_ssl_ticket_parse, &ticket_ctx);
345+
}
346+
}
347+
#endif
330348
return o;
331349
cleanup:
332350
mbedtls_pk_free(&o->pkey);

0 commit comments

Comments
 (0)