Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-8272653

SSLSession not invalidated after failed TLS resumption attempt

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: P4 P4
    • tbd
    • 18
    • security-libs
    • None

      This issue is a spin off of the issue reported via JDK-8270344

      The handshake session needs to be set correctly if the fatal alert handler is going to invalidate the correct session.

      The core issue in JDK-8270344 can be resolved by always sending the highest client supported TLS protocol version in the ClientHello legacy protocol version field.

      Dev asked that these two issues be split out into separate bugs.

            coffeys Sean Coffey
            coffeys Sean Coffey
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: