Fix regression in TLS session ticket disabling
authorDaniel Gustafsson
Mon, 19 Aug 2024 10:55:11 +0000 (12:55 +0200)
committerDaniel Gustafsson
Mon, 19 Aug 2024 10:55:11 +0000 (12:55 +0200)
commit19021d28cdf0e84ebc498382826b936df62f5dba
tree5d73b280f11a81089630f0cecfb30966d5a01711
parent1cc73d15ea58ddc15f91269493811cef99987cb8
Fix regression in TLS session ticket disabling

Commit 274bbced disabled session tickets for TLSv1.3 on top of the
already disabled TLSv1.2 session tickets, but accidentally caused
a regression where TLSv1.2 session tickets were incorrectly sent.
Fix by unconditionally disabling TLSv1.2 session tickets and only
disable TLSv1.3 tickets when the right version of OpenSSL is used.

Backpatch to all supported branches.

Reported-by: Cameron Vogt
Reported-by: Fire Emerald
Reviewed-by: Jacob Champion
Discussion: https://postgr.es/m/DM6PR16MB3145CF62857226F350C710D1AB852@DM6PR16MB3145.namprd16.prod.outlook.com
Backpatch-through: v12
src/backend/libpq/be-secure-openssl.c