Skip to content

dnsdist: Set the DoH ticket rotation delay before loading tickets #8949

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Mar 19, 2020

Conversation

rgacogne
Copy link
Member

Short description

Before that change, we could have loaded DoH STEK from a file without properly setting the next rotation, causing a ticket rotation to happen during the first TLS session establishment.
This can be prevented by setting ticketsKeysRotationDelay=0.

Checklist

I have:

  • read the CONTRIBUTING.md document
  • compiled this code
  • tested this code
  • included documentation (including possible behaviour changes)
  • documented the code
  • added or modified regression test(s)
  • added or modified unit test(s)

Before that change, we could have loaded DoH STEK from a file without
properly setting the next rotation, causing a ticket rotation to
happen during the first TLS session establishment.
This can be prevented by setting `ticketsKeysRotationDelay=0`.
@rgacogne rgacogne added this to the dnsdist-1.4.x milestone Mar 18, 2020
@rgacogne rgacogne merged commit 1bfdded into PowerDNS:master Mar 19, 2020
@rgacogne rgacogne deleted the ddist-doh-rotation-delay branch March 19, 2020 08:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant