utls/testdata/Server-TLSv12-ALPN
Filippo Valsorda 65b9e15fc2 crypto/tls: reduce session ticket linkability
Ever since session ticket key rotation was introduced in CL 9072, we've
been including a prefix in every ticket to identify what key it's
encrypted with. It's a small privacy gain, but the cost of trial
decryptions is also small, especially since the first key is probably
the most frequently used.

Also reissue tickets on every resumption so that the next connection
can't be linked to all the previous ones. Again the privacy gain is
small but the performance cost is small and it comes with a reduction in
complexity.

For #60105

Change-Id: I852f297162d2b79a3d9bf61f6171e8ce94b2537a
Reviewed-on: https://go-review.googlesource.com/c/go/+/496817
Reviewed-by: Damien Neil <dneil@google.com>
Reviewed-by: Matthew Dempsky <mdempsky@google.com>
Run-TryBot: Damien Neil <dneil@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-05-24 23:56:24 +00:00

91 lines
6.8 KiB
Text

>>> Flow 1 (client to server)
00000000 16 03 01 00 9d 01 00 00 99 03 03 38 64 71 8a 57 |...........8dq.W|
00000010 cb 23 9d ce 7c 41 93 09 c0 a9 47 ca 56 db 97 12 |.#..|A....G.V...|
00000020 14 c8 8e 3a 5a 56 34 f7 ad a2 90 00 00 04 cc a8 |...:ZV4.........|
00000030 00 ff 01 00 00 6c 00 0b 00 04 03 00 01 02 00 0a |.....l..........|
00000040 00 0c 00 0a 00 1d 00 17 00 1e 00 19 00 18 00 23 |...............#|
00000050 00 00 00 10 00 10 00 0e 06 70 72 6f 74 6f 32 06 |.........proto2.|
00000060 70 72 6f 74 6f 31 00 16 00 00 00 17 00 00 00 0d |proto1..........|
00000070 00 30 00 2e 04 03 05 03 06 03 08 07 08 08 08 09 |.0..............|
00000080 08 0a 08 0b 08 04 08 05 08 06 04 01 05 01 06 01 |................|
00000090 03 03 02 03 03 01 02 01 03 02 02 02 04 02 05 02 |................|
000000a0 06 02 |..|
>>> Flow 2 (server to client)
00000000 16 03 03 00 48 02 00 00 44 03 03 00 00 00 00 00 |....H...D.......|
00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000020 00 00 00 44 4f 57 4e 47 52 44 01 00 cc a8 00 00 |...DOWNGRD......|
00000030 1c 00 23 00 00 ff 01 00 01 00 00 10 00 09 00 07 |..#.............|
00000040 06 70 72 6f 74 6f 31 00 0b 00 02 01 00 16 03 03 |.proto1.........|
00000050 02 59 0b 00 02 55 00 02 52 00 02 4f 30 82 02 4b |.Y...U..R..O0..K|
00000060 30 82 01 b4 a0 03 02 01 02 02 09 00 e8 f0 9d 3f |0..............?|
00000070 e2 5b ea a6 30 0d 06 09 2a 86 48 86 f7 0d 01 01 |.[..0...*.H.....|
00000080 0b 05 00 30 1f 31 0b 30 09 06 03 55 04 0a 13 02 |...0.1.0...U....|
00000090 47 6f 31 10 30 0e 06 03 55 04 03 13 07 47 6f 20 |Go1.0...U....Go |
000000a0 52 6f 6f 74 30 1e 17 0d 31 36 30 31 30 31 30 30 |Root0...16010100|
000000b0 30 30 30 30 5a 17 0d 32 35 30 31 30 31 30 30 30 |0000Z..250101000|
000000c0 30 30 30 5a 30 1a 31 0b 30 09 06 03 55 04 0a 13 |000Z0.1.0...U...|
000000d0 02 47 6f 31 0b 30 09 06 03 55 04 03 13 02 47 6f |.Go1.0...U....Go|
000000e0 30 81 9f 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 |0..0...*.H......|
000000f0 05 00 03 81 8d 00 30 81 89 02 81 81 00 db 46 7d |......0.......F}|
00000100 93 2e 12 27 06 48 bc 06 28 21 ab 7e c4 b6 a2 5d |...'.H..(!.~...]|
00000110 fe 1e 52 45 88 7a 36 47 a5 08 0d 92 42 5b c2 81 |..RE.z6G....B[..|
00000120 c0 be 97 79 98 40 fb 4f 6d 14 fd 2b 13 8b c2 a5 |...y.@.Om..+....|
00000130 2e 67 d8 d4 09 9e d6 22 38 b7 4a 0b 74 73 2b c2 |.g....."8.J.ts+.|
00000140 34 f1 d1 93 e5 96 d9 74 7b f3 58 9f 6c 61 3c c0 |4......t{.X.la<.|
00000150 b0 41 d4 d9 2b 2b 24 23 77 5b 1c 3b bd 75 5d ce |.A..++$#w[.;.u].|
00000160 20 54 cf a1 63 87 1d 1e 24 c4 f3 1d 1a 50 8b aa | T..c...$....P..|
00000170 b6 14 43 ed 97 a7 75 62 f4 14 c8 52 d7 02 03 01 |..C...ub...R....|
00000180 00 01 a3 81 93 30 81 90 30 0e 06 03 55 1d 0f 01 |.....0..0...U...|
00000190 01 ff 04 04 03 02 05 a0 30 1d 06 03 55 1d 25 04 |........0...U.%.|
000001a0 16 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b |.0...+.........+|
000001b0 06 01 05 05 07 03 02 30 0c 06 03 55 1d 13 01 01 |.......0...U....|
000001c0 ff 04 02 30 00 30 19 06 03 55 1d 0e 04 12 04 10 |...0.0...U......|
000001d0 9f 91 16 1f 43 43 3e 49 a6 de 6d b6 80 d7 9f 60 |....CC>I..m....`|
000001e0 30 1b 06 03 55 1d 23 04 14 30 12 80 10 48 13 49 |0...U.#..0...H.I|
000001f0 4d 13 7e 16 31 bb a3 01 d5 ac ab 6e 7b 30 19 06 |M.~.1......n{0..|
00000200 03 55 1d 11 04 12 30 10 82 0e 65 78 61 6d 70 6c |.U....0...exampl|
00000210 65 2e 67 6f 6c 61 6e 67 30 0d 06 09 2a 86 48 86 |e.golang0...*.H.|
00000220 f7 0d 01 01 0b 05 00 03 81 81 00 9d 30 cc 40 2b |............0.@+|
00000230 5b 50 a0 61 cb ba e5 53 58 e1 ed 83 28 a9 58 1a |[P.a...SX...(.X.|
00000240 a9 38 a4 95 a1 ac 31 5a 1a 84 66 3d 43 d3 2d d9 |.8....1Z..f=C.-.|
00000250 0b f2 97 df d3 20 64 38 92 24 3a 00 bc cf 9c 7d |..... d8.$:....}|
00000260 b7 40 20 01 5f aa d3 16 61 09 a2 76 fd 13 c3 cc |.@ ._...a..v....|
00000270 e1 0c 5c ee b1 87 82 f1 6c 04 ed 73 bb b3 43 77 |..\.....l..s..Cw|
00000280 8d 0c 1c f1 0f a1 d8 40 83 61 c9 4c 72 2b 9d ae |.......@.a.Lr+..|
00000290 db 46 06 06 4d f4 c1 b3 3e c0 d1 bd 42 d4 db fe |.F..M...>...B...|
000002a0 3d 13 60 84 5c 21 d3 3b e9 fa e7 16 03 03 00 ac |=.`.\!.;........|
000002b0 0c 00 00 a8 03 00 1d 20 2f e5 7d a3 47 cd 62 43 |....... /.}.G.bC|
000002c0 15 28 da ac 5f bb 29 07 30 ff f6 84 af c4 cf c2 |.(.._.).0.......|
000002d0 ed 90 99 5f 58 cb 3b 74 08 04 00 80 36 d7 55 53 |..._X.;t....6.US|
000002e0 60 3e 9a ca 01 8e f9 f4 16 d0 66 30 12 29 ae 0d |`>........f0.)..|
000002f0 23 f4 73 c6 d2 74 03 79 b5 b9 27 f6 33 e3 35 2e |#.s..t.y..'.3.5.|
00000300 8e d8 d0 30 b6 9e cb 96 99 91 d7 3c 3e ec 1f b4 |...0.......<>...|
00000310 b0 82 04 03 b3 f4 d6 60 38 9e d5 1a 38 fe ac ef |.......`8...8...|
00000320 10 e9 02 94 c5 8a b7 cd 69 cd 1d de 4f 61 5e eb |........i...Oa^.|
00000330 57 31 e7 de 6d 9a e4 d9 9a 09 c9 3d 3a a6 f1 65 |W1..m......=:..e|
00000340 95 1a 54 c3 bf 7c a9 22 47 90 d4 09 65 14 54 cc |..T..|."G...e.T.|
00000350 05 1f 73 1a e0 b9 9e f9 9a 81 be 91 16 03 03 00 |..s.............|
00000360 04 0e 00 00 00 |.....|
>>> Flow 3 (client to server)
00000000 16 03 03 00 25 10 00 00 21 20 79 2b 97 00 d7 66 |....%...! y+...f|
00000010 f9 ca 21 3c 1a 2b 60 7a e1 32 73 2b 7f f7 65 19 |..!<.+`z.2s+..e.|
00000020 08 ad 52 39 aa a9 8a 0b 9f 44 14 03 03 00 01 01 |..R9.....D......|
00000030 16 03 03 00 20 6e f1 de c4 b0 35 42 12 37 f2 e1 |.... n....5B.7..|
00000040 36 d7 4c 4e 11 98 72 ec 12 6c 2d 5e 11 3b c4 a4 |6.LN..r..l-^.;..|
00000050 9a 35 d5 5d 1c |.5.].|
>>> Flow 4 (server to client)
00000000 16 03 03 00 7b 04 00 00 77 00 00 00 00 00 71 00 |....{...w.....q.|
00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 94 |................|
00000020 6f e0 18 83 51 ed 14 ef 68 ca 42 c5 4c 8f d6 48 |o...Q...h.B.L..H|
00000030 3e 65 16 36 87 11 c3 53 8c 8f 44 1a f5 6e 92 65 |>e.6...S..D..n.e|
00000040 22 87 99 5f 58 18 48 86 79 d9 36 1e 23 4a 87 42 |".._X.H.y.6.#J.B|
00000050 18 45 f6 03 2b e5 a5 55 b4 59 62 b4 db 49 38 16 |.E..+..U.Yb..I8.|
00000060 2d d9 6b d5 66 55 c7 b9 d8 f1 03 6a 78 ea b9 93 |-.k.fU.....jx...|
00000070 f4 1a 8c d3 79 91 b4 37 42 e9 84 0f ea d1 04 ce |....y..7B.......|
00000080 14 03 03 00 01 01 16 03 03 00 20 f4 ff 37 5f 7c |.......... ..7_||
00000090 c6 6a b3 31 5f 06 51 62 f2 76 a2 cf da a3 a5 60 |.j.1_.Qb.v.....`|
000000a0 de 5b 6b bf 0d 03 2e ce de 9e 90 17 03 03 00 1d |.[k.............|
000000b0 7e 9f a9 87 fc e1 e8 84 7a 81 77 70 4a d1 52 cf |~.......z.wpJ.R.|
000000c0 ba c2 0b f6 99 2f 99 cb fb 73 25 c7 1d 15 03 03 |...../...s%.....|
000000d0 00 12 ac 41 7f af d0 87 25 e3 82 f4 c9 e5 fa ef |...A....%.......|
000000e0 d2 89 53 e6 |..S.|