From 9b69b3e9690021456ab1086aeb1125a9753f9ae0 Mon Sep 17 00:00:00 2001 From: Nikos Mavrogiannopoulos Date: Tue, 3 Jul 2018 10:22:04 +0200 Subject: doc: mention session ticket behavior under TLS1.3 Signed-off-by: Nikos Mavrogiannopoulos --- doc/cha-intro-tls.texi | 3 +++ 1 file changed, 3 insertions(+) diff --git a/doc/cha-intro-tls.texi b/doc/cha-intro-tls.texi index 0c82f0853b..b95abc6b81 100644 --- a/doc/cha-intro-tls.texi +++ b/doc/cha-intro-tls.texi @@ -464,6 +464,9 @@ regularly. Since version 3.1.3 GnuTLS clients transparently support session tickets, unless forward secrecy is explicitly requested (with the PFS priority string). +Under TLS 1.3 session tickets are mandatory for session resumption, and they +do not share the forward secrecy concerns as with TLS 1.2 or earlier. + @node HeartBeat @subsection HeartBeat @cindex TLS extensions -- cgit v1.2.1