Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dnsdist: Set the DoH ticket rotation delay before loading tickets #8949

Merged
merged 1 commit into from Mar 19, 2020

Conversation

rgacogne
Copy link
Member

@rgacogne rgacogne commented Mar 18, 2020

Short description

Before that change, we could have loaded DoH STEK from a file without properly setting the next rotation, causing a ticket rotation to happen during the first TLS session establishment.
This can be prevented by setting ticketsKeysRotationDelay=0.

Checklist

I have:

  • read the CONTRIBUTING.md document
  • compiled this code
  • tested this code
  • included documentation (including possible behaviour changes)
  • documented the code
  • added or modified regression test(s)
  • added or modified unit test(s)

Before that change, we could have loaded DoH STEK from a file without
properly setting the next rotation, causing a ticket rotation to
happen during the first TLS session establishment.
This can be prevented by setting `ticketsKeysRotationDelay=0`.
@rgacogne rgacogne added this to the dnsdist-1.4.x milestone Mar 18, 2020
@rgacogne rgacogne merged commit 1bfdded into PowerDNS:master Mar 19, 2020
25 checks passed
@rgacogne rgacogne deleted the ddist-doh-rotation-delay branch Mar 19, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant