Re: Some TLS servers are intolerant to SSL/TLS session caching

2014-01-14 Thread alvesfonseca
Hi folks, Last year I faced a similar problem. I posted in the list, but it remains unsolved. >> BOM > Subject: Thunderbird stalls when an IMAPS server doesn't support resume Hi folks, I sent the following message to dev-apps-thund and, as I didn't

Re: Some TLS servers are intolerant to SSL/TLS session caching

2014-01-13 Thread Julien Pierre
Kai, On 1/12/2014 03:26, Kai Engert wrote: Have you ever seen a TLS server that was incompatible with TLS session IDs? No. Do you agree this is bug on the server side? Yes. RFC 5246 section 7.3 says this : The client sends a ClientHello using the Session ID of the session to be resume

Some TLS servers are intolerant to SSL/TLS session caching

2014-01-12 Thread Kai Engert
Have you ever seen a TLS server that was incompatible with TLS session IDs? I helped to analyze bug 858394 (with the help of ssltap), where initial connections to a TLS server work, but attempts to reconnect fail. If the client includes a non-null session ID parameter in the client hello message,