Skip to content

Cache SSL_CREDENTIAL selected during handshake so getSelectedCredential works post-handshake - #1020

Draft
choulos wants to merge 5 commits into
netty:mainfrom
choulos:achoulos/cache-selected-credential
Draft

choulos wants to merge 5 commits into
netty:mainfrom
choulos:achoulos/cache-selected-credential

Conversation

@choulos

@choulos choulos commented Oct 8, 2026 •

Copy link
Copy Markdown

We would like to know which SSL Credential was selected post-handshake within netty, so that we may accurately track the effects of rolling out BoringSSL SSL Credential API to more endpoints.

SSL.getSelectedCredential wraps SSL_get0_selected_credential, which reads the handshake state. BoringSSL frees that state before SSL_do_handshake returns, so the call returns 0 once the handshake has completed, for both TLS 1.2 and 1.3.

Each credential created by SSLCredential.newX509() or newDelegated() now gets a unique id, stored in credential ex_data. When enabled with SSLContext.setRecordSelectedCredential, ssl_info_callback records the selected credential's id on SSL_CB_HANDSHAKE_DONE, overwriting it on every handshake. SSL.getSelectedCredentialId returns it. tcnative takes no new references on the credential, and callers map the id to their own metadata.

Recording is off by default, following the setUseTasks pattern. The id is stored in existing padding in tcn_ssl_state_t, so the struct size is unchanged, and when disabled the cost is one flag check per completed handshake.

…al works post-handshake

SSL_get0_selected_credential reads the handshake state, which BoringSSL frees
before SSL_do_handshake returns, so SSL.getSelectedCredential always returned 0
once the handshake completed.

Sample the credential in ssl_info_callback on SSL_CB_HANDSHAKE_DONE, hold a ref in
tcn_ssl_state_t and release it in free_ssl_state. On renegotiation the previous
ref is released and replaced, so the cache reflects the most recent completed
handshake. getSelectedCredential tries the live lookup first (non-NULL only while
the handshake state exists) and falls back to the cached credential.
@choulos
choulos force-pushed the achoulos/cache-selected-credential branch from 871a40e to dda31e3 Compare October 8, 2026 17:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant