Skip to content

Ingela/ssl/hardening/otp 20289 - #11478

Merged
IngelaAndin merged 17 commits into
erlang:maintfrom
IngelaAndin:ingela/ssl/hardening/OTP-20289
Aug 24, 2026
Merged

Ingela/ssl/hardening/otp 20289#11478
IngelaAndin merged 17 commits into
erlang:maintfrom
IngelaAndin:ingela/ssl/hardening/OTP-20289

Conversation

@IngelaAndin

Copy link
Copy Markdown
Contributor

Some hardening commits planed to backport to supported relases.

@IngelaAndin IngelaAndin self-assigned this Aug 12, 2026
@IngelaAndin IngelaAndin added the team:PS Assigned to OTP team PS label Aug 12, 2026
@github-actions

github-actions Bot commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

CT Test Results

    2 files     67 suites   25m 18s ⏱️
  838 tests   792 ✅  46 💤 0 ❌
4 336 runs  3 372 ✅ 964 💤 0 ❌

Results for commit b275ec5.

♻️ This comment has been updated with latest results.

To speed up review, make sure that you have read Contributing to Erlang/OTP and that all checks pass.

See the TESTING and DEVELOPMENT HowTo guides for details about how to run test locally.

Artifacts

// Erlang/OTP Github Action Bot

@IngelaAndin
IngelaAndin force-pushed the ingela/ssl/hardening/OTP-20289 branch 25 times, most recently from 28409be to ee66261 Compare August 17, 2026 07:26
@IngelaAndin
IngelaAndin requested a review from u3s August 17, 2026 09:16
@IngelaAndin
IngelaAndin force-pushed the ingela/ssl/hardening/OTP-20289 branch 2 times, most recently from 2f0e284 to e687c9a Compare August 21, 2026 12:23
@IngelaAndin IngelaAndin added the testing currently being tested, tag is used by OTP internal CI label Aug 21, 2026
@IngelaAndin
IngelaAndin force-pushed the ingela/ssl/hardening/OTP-20289 branch from e687c9a to afc326f Compare August 21, 2026 13:40
u3s
u3s previously approved these changes Aug 21, 2026
Add missing format_status function to avoid unwanted logging.

Also use new format_staus/1 instead of deprecated format_status/2.
Add sanity checks.

Correct documentation for logging.

Ignore invalid CRL input.
Avoid bignums and floats.
Handle termination of clients that locked a ticket for
PSK resumption attempt when using automated client ticket
store.
By default run TLS-1.3 instead of TLS-1.2,
but keep TLS-1.2 support for smoother upgrade.

Make sure net_kernel allowed is honored in all cases.
Add missing state update
Could cause connection failure instead of DTLS alert ignoring.

Fix fragment reassembling bug and handle unexpected epoch 0 message.
Mitigate DoS attack possiblities.
Correct TLS-1.3 ALPN check.

Add missing client santity check.

Various MUST alerts for extension handling.
Better safe guard, try of to narrow here.
Ensure signature algs are checked for intermediates.
If user hade own verify fun these would previously
be missed.

Add missing extension assertion.
Refocus on what parts are not yet implemented
instead of trying to list everthing that is.

Add note about importance of using lates patch version.
…phr_spec messages

Found when looking into issue 11075
@IngelaAndin
IngelaAndin force-pushed the ingela/ssl/hardening/OTP-20289 branch 2 times, most recently from a8c7889 to 6efa8bf Compare August 22, 2026 19:52
Comment thread lib/ssl/test/ssl_session_SUITE.erl Outdated
Make session_reuse disabled by default when client certificates
are requierd, until extend master secret can be implemented.
But best option is to run TLS-1.3.
@IngelaAndin
IngelaAndin force-pushed the ingela/ssl/hardening/OTP-20289 branch from 6efa8bf to b275ec5 Compare August 24, 2026 06:37
@IngelaAndin
IngelaAndin requested a review from dgud August 24, 2026 06:38
@IngelaAndin
IngelaAndin merged commit 8c9a51e into erlang:maint Aug 24, 2026
31 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

team:PS Assigned to OTP team PS testing currently being tested, tag is used by OTP internal CI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants