Support TLS Resume with client certificates on Linux - #102656

Merged
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux
Jun 12, 2024
Merged

Support TLS Resume with client certificates on Linux#102656
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux

Conversation

@rzikm

@rzikmrzikm commented May 24, 2024

Copy link
Copy Markdown
Member

Closes#94561.

This PR enables TLS resume on Linux if client certificate is provided. The feature is triggered if local certificate selection routine manages to select a certificate, i.e. either of these situations:

  • ClientCertificateContext
  • LocalCertificateSelectionCallback returns non-null certificate on first call (otherwise selection based on server cert/acceptable issuers is assumed and fresh SSL_CTX is always used)
  • ClientCertificates collection has at least one certificate (and first one with private key is used)

The feature is enabled by caching SSL_CTX as before, certificate thumbprint has been added to the cache key to mirror what we do on Windows. The caching code has been reused from MsQuicConfiguration cache (and in further PR can be unified with the caching code we have for SslStream credentials on Windows).

I stressed the caching code under a dedicated program, there does not seem to be any leakage.

@rzikm

rzikm commented May 24, 2024

Copy link
Copy Markdown
MemberAuthor

Looks like TLS 1.3 works as well. (Windows server, Linux client, client cert required)

image

@rzikm
rzikm requested a review from wfurtMay 24, 2024 13:14
Comment threadsrc/native/libs/System.Security.Cryptography.Native/openssl.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.h Outdated
@wfurt

Copy link
Copy Markdown
Member

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

@rzikm

rzikm commented May 30, 2024

Copy link
Copy Markdown
MemberAuthor

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

I meant that Linux .NET server does not issue resumption tokens in TLS 1.3, so I had to test against different server (Windows in this case).

Edit: my bad, it turns out that the resumption ticket was not transmitted because we close the connection without actually transmitting any user data, adding a ping-pong to the tests fixed the problem.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries coreclr-outerloop

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp list

@azure-pipelines

Copy link
Copy Markdown
CI/CD Pipelines for this repository:

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

1 similar comment
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g Test failures are all unrelated, relevant stages (System.Net.Security.Tests) all pass

@LoopedBard3

LoopedBard3 commented Jun 18, 2024

Copy link
Copy Markdown
Member

Related regression: dotnet/perf-autofiling-issues#36400 (Only the SSLStreamTests)

Linux Arm64: dotnet/perf-autofiling-issues#36652

@rzikm

rzikm commented Jun 19, 2024

Copy link
Copy Markdown
MemberAuthor

I realize I did not post any measurements here, so here we are:

// * Summary *
BenchmarkDotNet v0.13.13-nightly.20240311.145, Ubuntu 22.04.4 LTS (Jammy Jellyfish)
Intel Core i9-10900K CPU 3.70GHz, 1 CPU, 20 logical and 10 physical cores
.NET SDK 9.0.100-preview.5.24307.3
[Host] : .NET 9.0.0 (9.0.24.30607), X64 RyuJIT AVX2
Job-DZDDGH : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
Job-HPXMZE : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
PowerPlanMode=00000000-0000-0000-0000-000000000000 IterationTime=250ms MaxIterationCount=20
MinIterationCount=15 WarmupCount=1
| Method | Job | Toolchain | Mean | Error | StdDev | Median | Min | Max | Ratio | RatioSD | Allocated | Alloc Ratio |
|--------------------------------------- |----------- |--------------- |----------:|----------:|----------:|----------:|-----------:|----------:|------:|--------:|----------:|------------:|
| DefaultHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.017 ms | 0.0275 ms | 0.0294 ms | 1.008 ms | 0.9759 ms | 1.082 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 1.054 ms | 0.0207 ms | 0.0213 ms | 1.053 ms | 1.0240 ms | 1.109 ms | 1.04 | 0.03 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.046 ms | 0.0328 ms | 0.0350 ms | 1.039 ms | 0.9988 ms | 1.130 ms | 1.00 | 0.05 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 1.045 ms | 0.0202 ms | 0.0168 ms | 1.050 ms | 1.0154 ms | 1.074 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.394 ms | 0.0269 ms | 0.0225 ms | 1.395 ms | 1.3559 ms | 1.441 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 4.792 ms | 0.2019 ms | 0.2244 ms | 4.754 ms | 4.4838 ms | 5.289 ms | 3.44 | 0.17 | 6.27 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.398 ms | 0.0273 ms | 0.0256 ms | 1.394 ms | 1.3611 ms | 1.445 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 4.716 ms | 0.0982 ms | 0.1091 ms | 4.686 ms | 4.5305 ms | 4.914 ms | 3.37 | 0.10 | 6.26 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 5.715 ms | 0.0660 ms | 0.0551 ms | 5.705 ms | 5.6337 ms | 5.832 ms | 1.00 | 0.01 | 9.66 KB | 1.00 |
| DefaultHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 5.949 ms | 0.1222 ms | 0.1358 ms | 5.960 ms | 5.7571 ms | 6.177 ms | 1.04 | 0.03 | 9.67 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 5.904 ms | 0.1713 ms | 0.1904 ms | 5.835 ms | 5.6978 ms | 6.335 ms | 1.00 | 0.04 | 9.68 KB | 1.00 |
| DefaultHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 5.862 ms | 0.1116 ms | 0.0932 ms | 5.828 ms | 5.7339 ms | 6.003 ms | 0.99 | 0.03 | 9.66 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 10.854 ms | 0.2105 ms | 0.1969 ms | 10.804 ms | 10.5719 ms | 11.251 ms | 1.00 | 0.02 | 17.34 KB | 1.00 |
| DefaultMutualHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 11.575 ms | 0.2257 ms | 0.2001 ms | 11.556 ms | 11.2971 ms | 11.996 ms | 1.07 | 0.03 | 17.18 KB | 0.99 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 10.850 ms | 0.2151 ms | 0.2012 ms | 10.801 ms | 10.5470 ms | 11.177 ms | 1.00 | 0.03 | 17.36 KB | 1.00 |
| DefaultMutualHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 11.306 ms | 0.2226 ms | 0.2475 ms | 11.337 ms | 10.8917 ms | 11.872 ms | 1.04 | 0.03 | 15.91 KB | 0.92 |
| | | | | | | | | | | | | |
| DefaultHandshakePipeAsync | Job-DZDDGH | /9.0.0/corerun | 5.901 ms | 0.1145 ms | 0.1125 ms | 5.894 ms | 5.7267 ms | 6.163 ms | 1.00 | 0.03 | 9.96 KB | 1.00 |
| DefaultHandshakePipeAsync | Job-HPXMZE | /main/corerun | 6.032 ms | 0.1747 ms | 0.2012 ms | 6.001 ms | 5.7647 ms | 6.430 ms | 1.02 | 0.04 | 9.98 KB | 1.00 |

The main brach is main excluding this change, 9.0.0 includes this PR and #103720. Notice mainly the Context benchmarks, and the (new, PR to be raised soon) DefaultMutualHandshakeContext* benchmarks, where the new TLS resume shines. The amount of allocations is a bit weird, I might look into these later when I have time.

@rzikm

Copy link
Copy Markdown
MemberAuthor

cc @stephentoub, @ManickaP, since this might look well in your future blog posts

@stephentoub

Copy link
Copy Markdown
Member

already on my list :)

@karelzkarelz added this to the 9.0.0 milestone Jun 24, 2024
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 25, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Sep 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Net.Securitycryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.trackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support TLS Resume with client certificates on Linux

7 participants

@rzikm@wfurt@LoopedBard3@stephentoub@vcsjones@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Support TLS Resume with client certificates on Linux - #102656

Merged
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux
Jun 12, 2024
Merged

Support TLS Resume with client certificates on Linux#102656
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux

Conversation

@rzikm

@rzikmrzikm commented May 24, 2024

Copy link
Copy Markdown
Member

Closes#94561.

This PR enables TLS resume on Linux if client certificate is provided. The feature is triggered if local certificate selection routine manages to select a certificate, i.e. either of these situations:

  • ClientCertificateContext
  • LocalCertificateSelectionCallback returns non-null certificate on first call (otherwise selection based on server cert/acceptable issuers is assumed and fresh SSL_CTX is always used)
  • ClientCertificates collection has at least one certificate (and first one with private key is used)

The feature is enabled by caching SSL_CTX as before, certificate thumbprint has been added to the cache key to mirror what we do on Windows. The caching code has been reused from MsQuicConfiguration cache (and in further PR can be unified with the caching code we have for SslStream credentials on Windows).

I stressed the caching code under a dedicated program, there does not seem to be any leakage.

@rzikm

rzikm commented May 24, 2024

Copy link
Copy Markdown
MemberAuthor

Looks like TLS 1.3 works as well. (Windows server, Linux client, client cert required)

image

@rzikm
rzikm requested a review from wfurtMay 24, 2024 13:14
Comment threadsrc/native/libs/System.Security.Cryptography.Native/openssl.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.h Outdated
@wfurt

Copy link
Copy Markdown
Member

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

@rzikm

rzikm commented May 30, 2024

Copy link
Copy Markdown
MemberAuthor

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

I meant that Linux .NET server does not issue resumption tokens in TLS 1.3, so I had to test against different server (Windows in this case).

Edit: my bad, it turns out that the resumption ticket was not transmitted because we close the connection without actually transmitting any user data, adding a ping-pong to the tests fixed the problem.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries coreclr-outerloop

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp list

@azure-pipelines

Copy link
Copy Markdown
CI/CD Pipelines for this repository:

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

1 similar comment
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g Test failures are all unrelated, relevant stages (System.Net.Security.Tests) all pass

@LoopedBard3

LoopedBard3 commented Jun 18, 2024

Copy link
Copy Markdown
Member

Related regression: dotnet/perf-autofiling-issues#36400 (Only the SSLStreamTests)

Linux Arm64: dotnet/perf-autofiling-issues#36652

@rzikm

rzikm commented Jun 19, 2024

Copy link
Copy Markdown
MemberAuthor

I realize I did not post any measurements here, so here we are:

// * Summary *
BenchmarkDotNet v0.13.13-nightly.20240311.145, Ubuntu 22.04.4 LTS (Jammy Jellyfish)
Intel Core i9-10900K CPU 3.70GHz, 1 CPU, 20 logical and 10 physical cores
.NET SDK 9.0.100-preview.5.24307.3
[Host] : .NET 9.0.0 (9.0.24.30607), X64 RyuJIT AVX2
Job-DZDDGH : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
Job-HPXMZE : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
PowerPlanMode=00000000-0000-0000-0000-000000000000 IterationTime=250ms MaxIterationCount=20
MinIterationCount=15 WarmupCount=1
| Method | Job | Toolchain | Mean | Error | StdDev | Median | Min | Max | Ratio | RatioSD | Allocated | Alloc Ratio |
|--------------------------------------- |----------- |--------------- |----------:|----------:|----------:|----------:|-----------:|----------:|------:|--------:|----------:|------------:|
| DefaultHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.017 ms | 0.0275 ms | 0.0294 ms | 1.008 ms | 0.9759 ms | 1.082 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 1.054 ms | 0.0207 ms | 0.0213 ms | 1.053 ms | 1.0240 ms | 1.109 ms | 1.04 | 0.03 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.046 ms | 0.0328 ms | 0.0350 ms | 1.039 ms | 0.9988 ms | 1.130 ms | 1.00 | 0.05 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 1.045 ms | 0.0202 ms | 0.0168 ms | 1.050 ms | 1.0154 ms | 1.074 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.394 ms | 0.0269 ms | 0.0225 ms | 1.395 ms | 1.3559 ms | 1.441 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 4.792 ms | 0.2019 ms | 0.2244 ms | 4.754 ms | 4.4838 ms | 5.289 ms | 3.44 | 0.17 | 6.27 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.398 ms | 0.0273 ms | 0.0256 ms | 1.394 ms | 1.3611 ms | 1.445 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 4.716 ms | 0.0982 ms | 0.1091 ms | 4.686 ms | 4.5305 ms | 4.914 ms | 3.37 | 0.10 | 6.26 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 5.715 ms | 0.0660 ms | 0.0551 ms | 5.705 ms | 5.6337 ms | 5.832 ms | 1.00 | 0.01 | 9.66 KB | 1.00 |
| DefaultHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 5.949 ms | 0.1222 ms | 0.1358 ms | 5.960 ms | 5.7571 ms | 6.177 ms | 1.04 | 0.03 | 9.67 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 5.904 ms | 0.1713 ms | 0.1904 ms | 5.835 ms | 5.6978 ms | 6.335 ms | 1.00 | 0.04 | 9.68 KB | 1.00 |
| DefaultHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 5.862 ms | 0.1116 ms | 0.0932 ms | 5.828 ms | 5.7339 ms | 6.003 ms | 0.99 | 0.03 | 9.66 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 10.854 ms | 0.2105 ms | 0.1969 ms | 10.804 ms | 10.5719 ms | 11.251 ms | 1.00 | 0.02 | 17.34 KB | 1.00 |
| DefaultMutualHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 11.575 ms | 0.2257 ms | 0.2001 ms | 11.556 ms | 11.2971 ms | 11.996 ms | 1.07 | 0.03 | 17.18 KB | 0.99 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 10.850 ms | 0.2151 ms | 0.2012 ms | 10.801 ms | 10.5470 ms | 11.177 ms | 1.00 | 0.03 | 17.36 KB | 1.00 |
| DefaultMutualHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 11.306 ms | 0.2226 ms | 0.2475 ms | 11.337 ms | 10.8917 ms | 11.872 ms | 1.04 | 0.03 | 15.91 KB | 0.92 |
| | | | | | | | | | | | | |
| DefaultHandshakePipeAsync | Job-DZDDGH | /9.0.0/corerun | 5.901 ms | 0.1145 ms | 0.1125 ms | 5.894 ms | 5.7267 ms | 6.163 ms | 1.00 | 0.03 | 9.96 KB | 1.00 |
| DefaultHandshakePipeAsync | Job-HPXMZE | /main/corerun | 6.032 ms | 0.1747 ms | 0.2012 ms | 6.001 ms | 5.7647 ms | 6.430 ms | 1.02 | 0.04 | 9.98 KB | 1.00 |

The main brach is main excluding this change, 9.0.0 includes this PR and #103720. Notice mainly the Context benchmarks, and the (new, PR to be raised soon) DefaultMutualHandshakeContext* benchmarks, where the new TLS resume shines. The amount of allocations is a bit weird, I might look into these later when I have time.

@rzikm

Copy link
Copy Markdown
MemberAuthor

cc @stephentoub, @ManickaP, since this might look well in your future blog posts

@stephentoub

Copy link
Copy Markdown
Member

already on my list :)

@karelzkarelz added this to the 9.0.0 milestone Jun 24, 2024
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 25, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Sep 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Net.Securitycryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.trackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support TLS Resume with client certificates on Linux

7 participants

@rzikm@wfurt@LoopedBard3@stephentoub@vcsjones@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Support TLS Resume with client certificates on Linux - #102656

Merged
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux
Jun 12, 2024
Merged

Support TLS Resume with client certificates on Linux#102656
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux

Conversation

@rzikm

@rzikmrzikm commented May 24, 2024

Copy link
Copy Markdown
Member

Closes#94561.

This PR enables TLS resume on Linux if client certificate is provided. The feature is triggered if local certificate selection routine manages to select a certificate, i.e. either of these situations:

  • ClientCertificateContext
  • LocalCertificateSelectionCallback returns non-null certificate on first call (otherwise selection based on server cert/acceptable issuers is assumed and fresh SSL_CTX is always used)
  • ClientCertificates collection has at least one certificate (and first one with private key is used)

The feature is enabled by caching SSL_CTX as before, certificate thumbprint has been added to the cache key to mirror what we do on Windows. The caching code has been reused from MsQuicConfiguration cache (and in further PR can be unified with the caching code we have for SslStream credentials on Windows).

I stressed the caching code under a dedicated program, there does not seem to be any leakage.

@rzikm

rzikm commented May 24, 2024

Copy link
Copy Markdown
MemberAuthor

Looks like TLS 1.3 works as well. (Windows server, Linux client, client cert required)

image

@rzikm
rzikm requested a review from wfurtMay 24, 2024 13:14
Comment threadsrc/native/libs/System.Security.Cryptography.Native/openssl.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.h Outdated
@wfurt

Copy link
Copy Markdown
Member

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

@rzikm

rzikm commented May 30, 2024

Copy link
Copy Markdown
MemberAuthor

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

I meant that Linux .NET server does not issue resumption tokens in TLS 1.3, so I had to test against different server (Windows in this case).

Edit: my bad, it turns out that the resumption ticket was not transmitted because we close the connection without actually transmitting any user data, adding a ping-pong to the tests fixed the problem.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries coreclr-outerloop

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp list

@azure-pipelines

Copy link
Copy Markdown
CI/CD Pipelines for this repository:

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

1 similar comment
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g Test failures are all unrelated, relevant stages (System.Net.Security.Tests) all pass

@LoopedBard3

LoopedBard3 commented Jun 18, 2024

Copy link
Copy Markdown
Member

Related regression: dotnet/perf-autofiling-issues#36400 (Only the SSLStreamTests)

Linux Arm64: dotnet/perf-autofiling-issues#36652

@rzikm

rzikm commented Jun 19, 2024

Copy link
Copy Markdown
MemberAuthor

I realize I did not post any measurements here, so here we are:

// * Summary *
BenchmarkDotNet v0.13.13-nightly.20240311.145, Ubuntu 22.04.4 LTS (Jammy Jellyfish)
Intel Core i9-10900K CPU 3.70GHz, 1 CPU, 20 logical and 10 physical cores
.NET SDK 9.0.100-preview.5.24307.3
[Host] : .NET 9.0.0 (9.0.24.30607), X64 RyuJIT AVX2
Job-DZDDGH : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
Job-HPXMZE : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
PowerPlanMode=00000000-0000-0000-0000-000000000000 IterationTime=250ms MaxIterationCount=20
MinIterationCount=15 WarmupCount=1
| Method | Job | Toolchain | Mean | Error | StdDev | Median | Min | Max | Ratio | RatioSD | Allocated | Alloc Ratio |
|--------------------------------------- |----------- |--------------- |----------:|----------:|----------:|----------:|-----------:|----------:|------:|--------:|----------:|------------:|
| DefaultHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.017 ms | 0.0275 ms | 0.0294 ms | 1.008 ms | 0.9759 ms | 1.082 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 1.054 ms | 0.0207 ms | 0.0213 ms | 1.053 ms | 1.0240 ms | 1.109 ms | 1.04 | 0.03 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.046 ms | 0.0328 ms | 0.0350 ms | 1.039 ms | 0.9988 ms | 1.130 ms | 1.00 | 0.05 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 1.045 ms | 0.0202 ms | 0.0168 ms | 1.050 ms | 1.0154 ms | 1.074 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.394 ms | 0.0269 ms | 0.0225 ms | 1.395 ms | 1.3559 ms | 1.441 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 4.792 ms | 0.2019 ms | 0.2244 ms | 4.754 ms | 4.4838 ms | 5.289 ms | 3.44 | 0.17 | 6.27 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.398 ms | 0.0273 ms | 0.0256 ms | 1.394 ms | 1.3611 ms | 1.445 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 4.716 ms | 0.0982 ms | 0.1091 ms | 4.686 ms | 4.5305 ms | 4.914 ms | 3.37 | 0.10 | 6.26 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 5.715 ms | 0.0660 ms | 0.0551 ms | 5.705 ms | 5.6337 ms | 5.832 ms | 1.00 | 0.01 | 9.66 KB | 1.00 |
| DefaultHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 5.949 ms | 0.1222 ms | 0.1358 ms | 5.960 ms | 5.7571 ms | 6.177 ms | 1.04 | 0.03 | 9.67 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 5.904 ms | 0.1713 ms | 0.1904 ms | 5.835 ms | 5.6978 ms | 6.335 ms | 1.00 | 0.04 | 9.68 KB | 1.00 |
| DefaultHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 5.862 ms | 0.1116 ms | 0.0932 ms | 5.828 ms | 5.7339 ms | 6.003 ms | 0.99 | 0.03 | 9.66 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 10.854 ms | 0.2105 ms | 0.1969 ms | 10.804 ms | 10.5719 ms | 11.251 ms | 1.00 | 0.02 | 17.34 KB | 1.00 |
| DefaultMutualHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 11.575 ms | 0.2257 ms | 0.2001 ms | 11.556 ms | 11.2971 ms | 11.996 ms | 1.07 | 0.03 | 17.18 KB | 0.99 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 10.850 ms | 0.2151 ms | 0.2012 ms | 10.801 ms | 10.5470 ms | 11.177 ms | 1.00 | 0.03 | 17.36 KB | 1.00 |
| DefaultMutualHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 11.306 ms | 0.2226 ms | 0.2475 ms | 11.337 ms | 10.8917 ms | 11.872 ms | 1.04 | 0.03 | 15.91 KB | 0.92 |
| | | | | | | | | | | | | |
| DefaultHandshakePipeAsync | Job-DZDDGH | /9.0.0/corerun | 5.901 ms | 0.1145 ms | 0.1125 ms | 5.894 ms | 5.7267 ms | 6.163 ms | 1.00 | 0.03 | 9.96 KB | 1.00 |
| DefaultHandshakePipeAsync | Job-HPXMZE | /main/corerun | 6.032 ms | 0.1747 ms | 0.2012 ms | 6.001 ms | 5.7647 ms | 6.430 ms | 1.02 | 0.04 | 9.98 KB | 1.00 |

The main brach is main excluding this change, 9.0.0 includes this PR and #103720. Notice mainly the Context benchmarks, and the (new, PR to be raised soon) DefaultMutualHandshakeContext* benchmarks, where the new TLS resume shines. The amount of allocations is a bit weird, I might look into these later when I have time.

@rzikm

Copy link
Copy Markdown
MemberAuthor

cc @stephentoub, @ManickaP, since this might look well in your future blog posts

@stephentoub

Copy link
Copy Markdown
Member

already on my list :)

@karelzkarelz added this to the 9.0.0 milestone Jun 24, 2024
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 25, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Sep 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Net.Securitycryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.trackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support TLS Resume with client certificates on Linux

7 participants

@rzikm@wfurt@LoopedBard3@stephentoub@vcsjones@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Support TLS Resume with client certificates on Linux - #102656

Merged
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux
Jun 12, 2024
Merged

Support TLS Resume with client certificates on Linux#102656
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux

Conversation

@rzikm

@rzikmrzikm commented May 24, 2024

Copy link
Copy Markdown
Member

Closes#94561.

This PR enables TLS resume on Linux if client certificate is provided. The feature is triggered if local certificate selection routine manages to select a certificate, i.e. either of these situations:

  • ClientCertificateContext
  • LocalCertificateSelectionCallback returns non-null certificate on first call (otherwise selection based on server cert/acceptable issuers is assumed and fresh SSL_CTX is always used)
  • ClientCertificates collection has at least one certificate (and first one with private key is used)

The feature is enabled by caching SSL_CTX as before, certificate thumbprint has been added to the cache key to mirror what we do on Windows. The caching code has been reused from MsQuicConfiguration cache (and in further PR can be unified with the caching code we have for SslStream credentials on Windows).

I stressed the caching code under a dedicated program, there does not seem to be any leakage.

@rzikm

rzikm commented May 24, 2024

Copy link
Copy Markdown
MemberAuthor

Looks like TLS 1.3 works as well. (Windows server, Linux client, client cert required)

image

@rzikm
rzikm requested a review from wfurtMay 24, 2024 13:14
Comment threadsrc/native/libs/System.Security.Cryptography.Native/openssl.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.h Outdated
@wfurt

Copy link
Copy Markdown
Member

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

@rzikm

rzikm commented May 30, 2024

Copy link
Copy Markdown
MemberAuthor

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

I meant that Linux .NET server does not issue resumption tokens in TLS 1.3, so I had to test against different server (Windows in this case).

Edit: my bad, it turns out that the resumption ticket was not transmitted because we close the connection without actually transmitting any user data, adding a ping-pong to the tests fixed the problem.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries coreclr-outerloop

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp list

@azure-pipelines

Copy link
Copy Markdown
CI/CD Pipelines for this repository:

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

1 similar comment
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g Test failures are all unrelated, relevant stages (System.Net.Security.Tests) all pass

@LoopedBard3

LoopedBard3 commented Jun 18, 2024

Copy link
Copy Markdown
Member

Related regression: dotnet/perf-autofiling-issues#36400 (Only the SSLStreamTests)

Linux Arm64: dotnet/perf-autofiling-issues#36652

@rzikm

rzikm commented Jun 19, 2024

Copy link
Copy Markdown
MemberAuthor

I realize I did not post any measurements here, so here we are:

// * Summary *
BenchmarkDotNet v0.13.13-nightly.20240311.145, Ubuntu 22.04.4 LTS (Jammy Jellyfish)
Intel Core i9-10900K CPU 3.70GHz, 1 CPU, 20 logical and 10 physical cores
.NET SDK 9.0.100-preview.5.24307.3
[Host] : .NET 9.0.0 (9.0.24.30607), X64 RyuJIT AVX2
Job-DZDDGH : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
Job-HPXMZE : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
PowerPlanMode=00000000-0000-0000-0000-000000000000 IterationTime=250ms MaxIterationCount=20
MinIterationCount=15 WarmupCount=1
| Method | Job | Toolchain | Mean | Error | StdDev | Median | Min | Max | Ratio | RatioSD | Allocated | Alloc Ratio |
|--------------------------------------- |----------- |--------------- |----------:|----------:|----------:|----------:|-----------:|----------:|------:|--------:|----------:|------------:|
| DefaultHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.017 ms | 0.0275 ms | 0.0294 ms | 1.008 ms | 0.9759 ms | 1.082 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 1.054 ms | 0.0207 ms | 0.0213 ms | 1.053 ms | 1.0240 ms | 1.109 ms | 1.04 | 0.03 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.046 ms | 0.0328 ms | 0.0350 ms | 1.039 ms | 0.9988 ms | 1.130 ms | 1.00 | 0.05 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 1.045 ms | 0.0202 ms | 0.0168 ms | 1.050 ms | 1.0154 ms | 1.074 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.394 ms | 0.0269 ms | 0.0225 ms | 1.395 ms | 1.3559 ms | 1.441 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 4.792 ms | 0.2019 ms | 0.2244 ms | 4.754 ms | 4.4838 ms | 5.289 ms | 3.44 | 0.17 | 6.27 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.398 ms | 0.0273 ms | 0.0256 ms | 1.394 ms | 1.3611 ms | 1.445 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 4.716 ms | 0.0982 ms | 0.1091 ms | 4.686 ms | 4.5305 ms | 4.914 ms | 3.37 | 0.10 | 6.26 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 5.715 ms | 0.0660 ms | 0.0551 ms | 5.705 ms | 5.6337 ms | 5.832 ms | 1.00 | 0.01 | 9.66 KB | 1.00 |
| DefaultHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 5.949 ms | 0.1222 ms | 0.1358 ms | 5.960 ms | 5.7571 ms | 6.177 ms | 1.04 | 0.03 | 9.67 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 5.904 ms | 0.1713 ms | 0.1904 ms | 5.835 ms | 5.6978 ms | 6.335 ms | 1.00 | 0.04 | 9.68 KB | 1.00 |
| DefaultHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 5.862 ms | 0.1116 ms | 0.0932 ms | 5.828 ms | 5.7339 ms | 6.003 ms | 0.99 | 0.03 | 9.66 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 10.854 ms | 0.2105 ms | 0.1969 ms | 10.804 ms | 10.5719 ms | 11.251 ms | 1.00 | 0.02 | 17.34 KB | 1.00 |
| DefaultMutualHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 11.575 ms | 0.2257 ms | 0.2001 ms | 11.556 ms | 11.2971 ms | 11.996 ms | 1.07 | 0.03 | 17.18 KB | 0.99 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 10.850 ms | 0.2151 ms | 0.2012 ms | 10.801 ms | 10.5470 ms | 11.177 ms | 1.00 | 0.03 | 17.36 KB | 1.00 |
| DefaultMutualHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 11.306 ms | 0.2226 ms | 0.2475 ms | 11.337 ms | 10.8917 ms | 11.872 ms | 1.04 | 0.03 | 15.91 KB | 0.92 |
| | | | | | | | | | | | | |
| DefaultHandshakePipeAsync | Job-DZDDGH | /9.0.0/corerun | 5.901 ms | 0.1145 ms | 0.1125 ms | 5.894 ms | 5.7267 ms | 6.163 ms | 1.00 | 0.03 | 9.96 KB | 1.00 |
| DefaultHandshakePipeAsync | Job-HPXMZE | /main/corerun | 6.032 ms | 0.1747 ms | 0.2012 ms | 6.001 ms | 5.7647 ms | 6.430 ms | 1.02 | 0.04 | 9.98 KB | 1.00 |

The main brach is main excluding this change, 9.0.0 includes this PR and #103720. Notice mainly the Context benchmarks, and the (new, PR to be raised soon) DefaultMutualHandshakeContext* benchmarks, where the new TLS resume shines. The amount of allocations is a bit weird, I might look into these later when I have time.

@rzikm

Copy link
Copy Markdown
MemberAuthor

cc @stephentoub, @ManickaP, since this might look well in your future blog posts

@stephentoub

Copy link
Copy Markdown
Member

already on my list :)

@karelzkarelz added this to the 9.0.0 milestone Jun 24, 2024
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 25, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Sep 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Net.Securitycryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.trackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support TLS Resume with client certificates on Linux

7 participants

@rzikm@wfurt@LoopedBard3@stephentoub@vcsjones@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Support TLS Resume with client certificates on Linux - #102656

Merged
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux
Jun 12, 2024
Merged

Support TLS Resume with client certificates on Linux#102656
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux

Conversation

@rzikm

@rzikmrzikm commented May 24, 2024

Copy link
Copy Markdown
Member

Closes#94561.

This PR enables TLS resume on Linux if client certificate is provided. The feature is triggered if local certificate selection routine manages to select a certificate, i.e. either of these situations:

  • ClientCertificateContext
  • LocalCertificateSelectionCallback returns non-null certificate on first call (otherwise selection based on server cert/acceptable issuers is assumed and fresh SSL_CTX is always used)
  • ClientCertificates collection has at least one certificate (and first one with private key is used)

The feature is enabled by caching SSL_CTX as before, certificate thumbprint has been added to the cache key to mirror what we do on Windows. The caching code has been reused from MsQuicConfiguration cache (and in further PR can be unified with the caching code we have for SslStream credentials on Windows).

I stressed the caching code under a dedicated program, there does not seem to be any leakage.

@rzikm

rzikm commented May 24, 2024

Copy link
Copy Markdown
MemberAuthor

Looks like TLS 1.3 works as well. (Windows server, Linux client, client cert required)

image

@rzikm
rzikm requested a review from wfurtMay 24, 2024 13:14
Comment threadsrc/native/libs/System.Security.Cryptography.Native/openssl.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.h Outdated
@wfurt

Copy link
Copy Markdown
Member

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

@rzikm

rzikm commented May 30, 2024

Copy link
Copy Markdown
MemberAuthor

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

I meant that Linux .NET server does not issue resumption tokens in TLS 1.3, so I had to test against different server (Windows in this case).

Edit: my bad, it turns out that the resumption ticket was not transmitted because we close the connection without actually transmitting any user data, adding a ping-pong to the tests fixed the problem.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries coreclr-outerloop

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp list

@azure-pipelines

Copy link
Copy Markdown
CI/CD Pipelines for this repository:

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

1 similar comment
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g Test failures are all unrelated, relevant stages (System.Net.Security.Tests) all pass

@LoopedBard3

LoopedBard3 commented Jun 18, 2024

Copy link
Copy Markdown
Member

Related regression: dotnet/perf-autofiling-issues#36400 (Only the SSLStreamTests)

Linux Arm64: dotnet/perf-autofiling-issues#36652

@rzikm

rzikm commented Jun 19, 2024

Copy link
Copy Markdown
MemberAuthor

I realize I did not post any measurements here, so here we are:

// * Summary *
BenchmarkDotNet v0.13.13-nightly.20240311.145, Ubuntu 22.04.4 LTS (Jammy Jellyfish)
Intel Core i9-10900K CPU 3.70GHz, 1 CPU, 20 logical and 10 physical cores
.NET SDK 9.0.100-preview.5.24307.3
[Host] : .NET 9.0.0 (9.0.24.30607), X64 RyuJIT AVX2
Job-DZDDGH : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
Job-HPXMZE : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
PowerPlanMode=00000000-0000-0000-0000-000000000000 IterationTime=250ms MaxIterationCount=20
MinIterationCount=15 WarmupCount=1
| Method | Job | Toolchain | Mean | Error | StdDev | Median | Min | Max | Ratio | RatioSD | Allocated | Alloc Ratio |
|--------------------------------------- |----------- |--------------- |----------:|----------:|----------:|----------:|-----------:|----------:|------:|--------:|----------:|------------:|
| DefaultHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.017 ms | 0.0275 ms | 0.0294 ms | 1.008 ms | 0.9759 ms | 1.082 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 1.054 ms | 0.0207 ms | 0.0213 ms | 1.053 ms | 1.0240 ms | 1.109 ms | 1.04 | 0.03 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.046 ms | 0.0328 ms | 0.0350 ms | 1.039 ms | 0.9988 ms | 1.130 ms | 1.00 | 0.05 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 1.045 ms | 0.0202 ms | 0.0168 ms | 1.050 ms | 1.0154 ms | 1.074 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.394 ms | 0.0269 ms | 0.0225 ms | 1.395 ms | 1.3559 ms | 1.441 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 4.792 ms | 0.2019 ms | 0.2244 ms | 4.754 ms | 4.4838 ms | 5.289 ms | 3.44 | 0.17 | 6.27 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.398 ms | 0.0273 ms | 0.0256 ms | 1.394 ms | 1.3611 ms | 1.445 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 4.716 ms | 0.0982 ms | 0.1091 ms | 4.686 ms | 4.5305 ms | 4.914 ms | 3.37 | 0.10 | 6.26 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 5.715 ms | 0.0660 ms | 0.0551 ms | 5.705 ms | 5.6337 ms | 5.832 ms | 1.00 | 0.01 | 9.66 KB | 1.00 |
| DefaultHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 5.949 ms | 0.1222 ms | 0.1358 ms | 5.960 ms | 5.7571 ms | 6.177 ms | 1.04 | 0.03 | 9.67 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 5.904 ms | 0.1713 ms | 0.1904 ms | 5.835 ms | 5.6978 ms | 6.335 ms | 1.00 | 0.04 | 9.68 KB | 1.00 |
| DefaultHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 5.862 ms | 0.1116 ms | 0.0932 ms | 5.828 ms | 5.7339 ms | 6.003 ms | 0.99 | 0.03 | 9.66 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 10.854 ms | 0.2105 ms | 0.1969 ms | 10.804 ms | 10.5719 ms | 11.251 ms | 1.00 | 0.02 | 17.34 KB | 1.00 |
| DefaultMutualHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 11.575 ms | 0.2257 ms | 0.2001 ms | 11.556 ms | 11.2971 ms | 11.996 ms | 1.07 | 0.03 | 17.18 KB | 0.99 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 10.850 ms | 0.2151 ms | 0.2012 ms | 10.801 ms | 10.5470 ms | 11.177 ms | 1.00 | 0.03 | 17.36 KB | 1.00 |
| DefaultMutualHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 11.306 ms | 0.2226 ms | 0.2475 ms | 11.337 ms | 10.8917 ms | 11.872 ms | 1.04 | 0.03 | 15.91 KB | 0.92 |
| | | | | | | | | | | | | |
| DefaultHandshakePipeAsync | Job-DZDDGH | /9.0.0/corerun | 5.901 ms | 0.1145 ms | 0.1125 ms | 5.894 ms | 5.7267 ms | 6.163 ms | 1.00 | 0.03 | 9.96 KB | 1.00 |
| DefaultHandshakePipeAsync | Job-HPXMZE | /main/corerun | 6.032 ms | 0.1747 ms | 0.2012 ms | 6.001 ms | 5.7647 ms | 6.430 ms | 1.02 | 0.04 | 9.98 KB | 1.00 |

The main brach is main excluding this change, 9.0.0 includes this PR and #103720. Notice mainly the Context benchmarks, and the (new, PR to be raised soon) DefaultMutualHandshakeContext* benchmarks, where the new TLS resume shines. The amount of allocations is a bit weird, I might look into these later when I have time.

@rzikm

Copy link
Copy Markdown
MemberAuthor

cc @stephentoub, @ManickaP, since this might look well in your future blog posts

@stephentoub

Copy link
Copy Markdown
Member

already on my list :)

@karelzkarelz added this to the 9.0.0 milestone Jun 24, 2024
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 25, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Sep 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Net.Securitycryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.trackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support TLS Resume with client certificates on Linux

7 participants

@rzikm@wfurt@LoopedBard3@stephentoub@vcsjones@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Support TLS Resume with client certificates on Linux - #102656

Merged
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux
Jun 12, 2024
Merged

Support TLS Resume with client certificates on Linux#102656
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux

Conversation

@rzikm

@rzikmrzikm commented May 24, 2024

Copy link
Copy Markdown
Member

Closes#94561.

This PR enables TLS resume on Linux if client certificate is provided. The feature is triggered if local certificate selection routine manages to select a certificate, i.e. either of these situations:

  • ClientCertificateContext
  • LocalCertificateSelectionCallback returns non-null certificate on first call (otherwise selection based on server cert/acceptable issuers is assumed and fresh SSL_CTX is always used)
  • ClientCertificates collection has at least one certificate (and first one with private key is used)

The feature is enabled by caching SSL_CTX as before, certificate thumbprint has been added to the cache key to mirror what we do on Windows. The caching code has been reused from MsQuicConfiguration cache (and in further PR can be unified with the caching code we have for SslStream credentials on Windows).

I stressed the caching code under a dedicated program, there does not seem to be any leakage.

@rzikm

rzikm commented May 24, 2024

Copy link
Copy Markdown
MemberAuthor

Looks like TLS 1.3 works as well. (Windows server, Linux client, client cert required)

image

@rzikm
rzikm requested a review from wfurtMay 24, 2024 13:14
Comment threadsrc/native/libs/System.Security.Cryptography.Native/openssl.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.h Outdated
@wfurt

Copy link
Copy Markdown
Member

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

@rzikm

rzikm commented May 30, 2024

Copy link
Copy Markdown
MemberAuthor

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

I meant that Linux .NET server does not issue resumption tokens in TLS 1.3, so I had to test against different server (Windows in this case).

Edit: my bad, it turns out that the resumption ticket was not transmitted because we close the connection without actually transmitting any user data, adding a ping-pong to the tests fixed the problem.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries coreclr-outerloop

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp list

@azure-pipelines

Copy link
Copy Markdown
CI/CD Pipelines for this repository:

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

1 similar comment
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g Test failures are all unrelated, relevant stages (System.Net.Security.Tests) all pass

@LoopedBard3

LoopedBard3 commented Jun 18, 2024

Copy link
Copy Markdown
Member

Related regression: dotnet/perf-autofiling-issues#36400 (Only the SSLStreamTests)

Linux Arm64: dotnet/perf-autofiling-issues#36652

@rzikm

rzikm commented Jun 19, 2024

Copy link
Copy Markdown
MemberAuthor

I realize I did not post any measurements here, so here we are:

// * Summary *
BenchmarkDotNet v0.13.13-nightly.20240311.145, Ubuntu 22.04.4 LTS (Jammy Jellyfish)
Intel Core i9-10900K CPU 3.70GHz, 1 CPU, 20 logical and 10 physical cores
.NET SDK 9.0.100-preview.5.24307.3
[Host] : .NET 9.0.0 (9.0.24.30607), X64 RyuJIT AVX2
Job-DZDDGH : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
Job-HPXMZE : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
PowerPlanMode=00000000-0000-0000-0000-000000000000 IterationTime=250ms MaxIterationCount=20
MinIterationCount=15 WarmupCount=1
| Method | Job | Toolchain | Mean | Error | StdDev | Median | Min | Max | Ratio | RatioSD | Allocated | Alloc Ratio |
|--------------------------------------- |----------- |--------------- |----------:|----------:|----------:|----------:|-----------:|----------:|------:|--------:|----------:|------------:|
| DefaultHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.017 ms | 0.0275 ms | 0.0294 ms | 1.008 ms | 0.9759 ms | 1.082 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 1.054 ms | 0.0207 ms | 0.0213 ms | 1.053 ms | 1.0240 ms | 1.109 ms | 1.04 | 0.03 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.046 ms | 0.0328 ms | 0.0350 ms | 1.039 ms | 0.9988 ms | 1.130 ms | 1.00 | 0.05 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 1.045 ms | 0.0202 ms | 0.0168 ms | 1.050 ms | 1.0154 ms | 1.074 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.394 ms | 0.0269 ms | 0.0225 ms | 1.395 ms | 1.3559 ms | 1.441 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 4.792 ms | 0.2019 ms | 0.2244 ms | 4.754 ms | 4.4838 ms | 5.289 ms | 3.44 | 0.17 | 6.27 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.398 ms | 0.0273 ms | 0.0256 ms | 1.394 ms | 1.3611 ms | 1.445 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 4.716 ms | 0.0982 ms | 0.1091 ms | 4.686 ms | 4.5305 ms | 4.914 ms | 3.37 | 0.10 | 6.26 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 5.715 ms | 0.0660 ms | 0.0551 ms | 5.705 ms | 5.6337 ms | 5.832 ms | 1.00 | 0.01 | 9.66 KB | 1.00 |
| DefaultHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 5.949 ms | 0.1222 ms | 0.1358 ms | 5.960 ms | 5.7571 ms | 6.177 ms | 1.04 | 0.03 | 9.67 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 5.904 ms | 0.1713 ms | 0.1904 ms | 5.835 ms | 5.6978 ms | 6.335 ms | 1.00 | 0.04 | 9.68 KB | 1.00 |
| DefaultHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 5.862 ms | 0.1116 ms | 0.0932 ms | 5.828 ms | 5.7339 ms | 6.003 ms | 0.99 | 0.03 | 9.66 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 10.854 ms | 0.2105 ms | 0.1969 ms | 10.804 ms | 10.5719 ms | 11.251 ms | 1.00 | 0.02 | 17.34 KB | 1.00 |
| DefaultMutualHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 11.575 ms | 0.2257 ms | 0.2001 ms | 11.556 ms | 11.2971 ms | 11.996 ms | 1.07 | 0.03 | 17.18 KB | 0.99 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 10.850 ms | 0.2151 ms | 0.2012 ms | 10.801 ms | 10.5470 ms | 11.177 ms | 1.00 | 0.03 | 17.36 KB | 1.00 |
| DefaultMutualHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 11.306 ms | 0.2226 ms | 0.2475 ms | 11.337 ms | 10.8917 ms | 11.872 ms | 1.04 | 0.03 | 15.91 KB | 0.92 |
| | | | | | | | | | | | | |
| DefaultHandshakePipeAsync | Job-DZDDGH | /9.0.0/corerun | 5.901 ms | 0.1145 ms | 0.1125 ms | 5.894 ms | 5.7267 ms | 6.163 ms | 1.00 | 0.03 | 9.96 KB | 1.00 |
| DefaultHandshakePipeAsync | Job-HPXMZE | /main/corerun | 6.032 ms | 0.1747 ms | 0.2012 ms | 6.001 ms | 5.7647 ms | 6.430 ms | 1.02 | 0.04 | 9.98 KB | 1.00 |

The main brach is main excluding this change, 9.0.0 includes this PR and #103720. Notice mainly the Context benchmarks, and the (new, PR to be raised soon) DefaultMutualHandshakeContext* benchmarks, where the new TLS resume shines. The amount of allocations is a bit weird, I might look into these later when I have time.

@rzikm

Copy link
Copy Markdown
MemberAuthor

cc @stephentoub, @ManickaP, since this might look well in your future blog posts

@stephentoub

Copy link
Copy Markdown
Member

already on my list :)

@karelzkarelz added this to the 9.0.0 milestone Jun 24, 2024
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 25, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Sep 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Net.Securitycryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.trackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support TLS Resume with client certificates on Linux

7 participants

@rzikm@wfurt@LoopedBard3@stephentoub@vcsjones@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Support TLS Resume with client certificates on Linux - #102656

Merged
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux
Jun 12, 2024
Merged

Support TLS Resume with client certificates on Linux#102656
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux

Conversation

@rzikm

@rzikmrzikm commented May 24, 2024

Copy link
Copy Markdown
Member

Closes#94561.

This PR enables TLS resume on Linux if client certificate is provided. The feature is triggered if local certificate selection routine manages to select a certificate, i.e. either of these situations:

  • ClientCertificateContext
  • LocalCertificateSelectionCallback returns non-null certificate on first call (otherwise selection based on server cert/acceptable issuers is assumed and fresh SSL_CTX is always used)
  • ClientCertificates collection has at least one certificate (and first one with private key is used)

The feature is enabled by caching SSL_CTX as before, certificate thumbprint has been added to the cache key to mirror what we do on Windows. The caching code has been reused from MsQuicConfiguration cache (and in further PR can be unified with the caching code we have for SslStream credentials on Windows).

I stressed the caching code under a dedicated program, there does not seem to be any leakage.

@rzikm

rzikm commented May 24, 2024

Copy link
Copy Markdown
MemberAuthor

Looks like TLS 1.3 works as well. (Windows server, Linux client, client cert required)

image

@rzikm
rzikm requested a review from wfurtMay 24, 2024 13:14
Comment threadsrc/native/libs/System.Security.Cryptography.Native/openssl.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.h Outdated
@wfurt

Copy link
Copy Markdown
Member

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

@rzikm

rzikm commented May 30, 2024

Copy link
Copy Markdown
MemberAuthor

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

I meant that Linux .NET server does not issue resumption tokens in TLS 1.3, so I had to test against different server (Windows in this case).

Edit: my bad, it turns out that the resumption ticket was not transmitted because we close the connection without actually transmitting any user data, adding a ping-pong to the tests fixed the problem.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries coreclr-outerloop

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp list

@azure-pipelines

Copy link
Copy Markdown
CI/CD Pipelines for this repository:

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

1 similar comment
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g Test failures are all unrelated, relevant stages (System.Net.Security.Tests) all pass

@LoopedBard3

LoopedBard3 commented Jun 18, 2024

Copy link
Copy Markdown
Member

Related regression: dotnet/perf-autofiling-issues#36400 (Only the SSLStreamTests)

Linux Arm64: dotnet/perf-autofiling-issues#36652

@rzikm

rzikm commented Jun 19, 2024

Copy link
Copy Markdown
MemberAuthor

I realize I did not post any measurements here, so here we are:

// * Summary *
BenchmarkDotNet v0.13.13-nightly.20240311.145, Ubuntu 22.04.4 LTS (Jammy Jellyfish)
Intel Core i9-10900K CPU 3.70GHz, 1 CPU, 20 logical and 10 physical cores
.NET SDK 9.0.100-preview.5.24307.3
[Host] : .NET 9.0.0 (9.0.24.30607), X64 RyuJIT AVX2
Job-DZDDGH : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
Job-HPXMZE : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
PowerPlanMode=00000000-0000-0000-0000-000000000000 IterationTime=250ms MaxIterationCount=20
MinIterationCount=15 WarmupCount=1
| Method | Job | Toolchain | Mean | Error | StdDev | Median | Min | Max | Ratio | RatioSD | Allocated | Alloc Ratio |
|--------------------------------------- |----------- |--------------- |----------:|----------:|----------:|----------:|-----------:|----------:|------:|--------:|----------:|------------:|
| DefaultHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.017 ms | 0.0275 ms | 0.0294 ms | 1.008 ms | 0.9759 ms | 1.082 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 1.054 ms | 0.0207 ms | 0.0213 ms | 1.053 ms | 1.0240 ms | 1.109 ms | 1.04 | 0.03 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.046 ms | 0.0328 ms | 0.0350 ms | 1.039 ms | 0.9988 ms | 1.130 ms | 1.00 | 0.05 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 1.045 ms | 0.0202 ms | 0.0168 ms | 1.050 ms | 1.0154 ms | 1.074 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.394 ms | 0.0269 ms | 0.0225 ms | 1.395 ms | 1.3559 ms | 1.441 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 4.792 ms | 0.2019 ms | 0.2244 ms | 4.754 ms | 4.4838 ms | 5.289 ms | 3.44 | 0.17 | 6.27 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.398 ms | 0.0273 ms | 0.0256 ms | 1.394 ms | 1.3611 ms | 1.445 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 4.716 ms | 0.0982 ms | 0.1091 ms | 4.686 ms | 4.5305 ms | 4.914 ms | 3.37 | 0.10 | 6.26 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 5.715 ms | 0.0660 ms | 0.0551 ms | 5.705 ms | 5.6337 ms | 5.832 ms | 1.00 | 0.01 | 9.66 KB | 1.00 |
| DefaultHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 5.949 ms | 0.1222 ms | 0.1358 ms | 5.960 ms | 5.7571 ms | 6.177 ms | 1.04 | 0.03 | 9.67 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 5.904 ms | 0.1713 ms | 0.1904 ms | 5.835 ms | 5.6978 ms | 6.335 ms | 1.00 | 0.04 | 9.68 KB | 1.00 |
| DefaultHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 5.862 ms | 0.1116 ms | 0.0932 ms | 5.828 ms | 5.7339 ms | 6.003 ms | 0.99 | 0.03 | 9.66 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 10.854 ms | 0.2105 ms | 0.1969 ms | 10.804 ms | 10.5719 ms | 11.251 ms | 1.00 | 0.02 | 17.34 KB | 1.00 |
| DefaultMutualHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 11.575 ms | 0.2257 ms | 0.2001 ms | 11.556 ms | 11.2971 ms | 11.996 ms | 1.07 | 0.03 | 17.18 KB | 0.99 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 10.850 ms | 0.2151 ms | 0.2012 ms | 10.801 ms | 10.5470 ms | 11.177 ms | 1.00 | 0.03 | 17.36 KB | 1.00 |
| DefaultMutualHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 11.306 ms | 0.2226 ms | 0.2475 ms | 11.337 ms | 10.8917 ms | 11.872 ms | 1.04 | 0.03 | 15.91 KB | 0.92 |
| | | | | | | | | | | | | |
| DefaultHandshakePipeAsync | Job-DZDDGH | /9.0.0/corerun | 5.901 ms | 0.1145 ms | 0.1125 ms | 5.894 ms | 5.7267 ms | 6.163 ms | 1.00 | 0.03 | 9.96 KB | 1.00 |
| DefaultHandshakePipeAsync | Job-HPXMZE | /main/corerun | 6.032 ms | 0.1747 ms | 0.2012 ms | 6.001 ms | 5.7647 ms | 6.430 ms | 1.02 | 0.04 | 9.98 KB | 1.00 |

The main brach is main excluding this change, 9.0.0 includes this PR and #103720. Notice mainly the Context benchmarks, and the (new, PR to be raised soon) DefaultMutualHandshakeContext* benchmarks, where the new TLS resume shines. The amount of allocations is a bit weird, I might look into these later when I have time.

@rzikm

Copy link
Copy Markdown
MemberAuthor

cc @stephentoub, @ManickaP, since this might look well in your future blog posts

@stephentoub

Copy link
Copy Markdown
Member

already on my list :)

@karelzkarelz added this to the 9.0.0 milestone Jun 24, 2024
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 25, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Sep 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Net.Securitycryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.trackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support TLS Resume with client certificates on Linux

7 participants

@rzikm@wfurt@LoopedBard3@stephentoub@vcsjones@bartonjs@karelz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Support TLS Resume with client certificates on Linux - #102656

Merged
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux
Jun 12, 2024
Merged

Support TLS Resume with client certificates on Linux#102656
rzikm merged 16 commits into
dotnet:mainfrom
rzikm:94561-Support-TLS-Resume-with-client-certificates-on-Linux

Conversation

@rzikm

@rzikmrzikm commented May 24, 2024

Copy link
Copy Markdown
Member

Closes#94561.

This PR enables TLS resume on Linux if client certificate is provided. The feature is triggered if local certificate selection routine manages to select a certificate, i.e. either of these situations:

  • ClientCertificateContext
  • LocalCertificateSelectionCallback returns non-null certificate on first call (otherwise selection based on server cert/acceptable issuers is assumed and fresh SSL_CTX is always used)
  • ClientCertificates collection has at least one certificate (and first one with private key is used)

The feature is enabled by caching SSL_CTX as before, certificate thumbprint has been added to the cache key to mirror what we do on Windows. The caching code has been reused from MsQuicConfiguration cache (and in further PR can be unified with the caching code we have for SslStream credentials on Windows).

I stressed the caching code under a dedicated program, there does not seem to be any leakage.

@rzikm

rzikm commented May 24, 2024

Copy link
Copy Markdown
MemberAuthor

Looks like TLS 1.3 works as well. (Windows server, Linux client, client cert required)

image

@rzikm
rzikm requested a review from wfurtMay 24, 2024 13:14
Comment threadsrc/native/libs/System.Security.Cryptography.Native/openssl.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.h Outdated
@wfurt

Copy link
Copy Markdown
Member

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

@rzikm

rzikm commented May 30, 2024

Copy link
Copy Markdown
MemberAuthor

I need to do a bit more testing (can't test TLS 1.3 resumption against .NET Linux server yet, as we support only stateful resumption yet).

I don't quite understand the comment. I thought we only support stateless e.g. tickets to avoid large server cache. But I would also think that it does not matter e.g. the resumption is possible in either way.

I meant that Linux .NET server does not issue resumption tokens in TLS 1.3, so I had to test against different server (Windows in this case).

Edit: my bad, it turns out that the resumption ticket was not transmitted because we close the connection without actually transmitting any user data, adding a ping-pong to the tests fixed the problem.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries coreclr-outerloop

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp list

@azure-pipelines

Copy link
Copy Markdown
CI/CD Pipelines for this repository:

@rzikm

rzikm commented Jun 6, 2024

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

1 similar comment
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g Test failures are all unrelated, relevant stages (System.Net.Security.Tests) all pass

@LoopedBard3

LoopedBard3 commented Jun 18, 2024

Copy link
Copy Markdown
Member

Related regression: dotnet/perf-autofiling-issues#36400 (Only the SSLStreamTests)

Linux Arm64: dotnet/perf-autofiling-issues#36652

@rzikm

rzikm commented Jun 19, 2024

Copy link
Copy Markdown
MemberAuthor

I realize I did not post any measurements here, so here we are:

// * Summary *
BenchmarkDotNet v0.13.13-nightly.20240311.145, Ubuntu 22.04.4 LTS (Jammy Jellyfish)
Intel Core i9-10900K CPU 3.70GHz, 1 CPU, 20 logical and 10 physical cores
.NET SDK 9.0.100-preview.5.24307.3
[Host] : .NET 9.0.0 (9.0.24.30607), X64 RyuJIT AVX2
Job-DZDDGH : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
Job-HPXMZE : .NET 9.0.0 (42.42.42.42424), X64 RyuJIT AVX2
PowerPlanMode=00000000-0000-0000-0000-000000000000 IterationTime=250ms MaxIterationCount=20
MinIterationCount=15 WarmupCount=1
| Method | Job | Toolchain | Mean | Error | StdDev | Median | Min | Max | Ratio | RatioSD | Allocated | Alloc Ratio |
|--------------------------------------- |----------- |--------------- |----------:|----------:|----------:|----------:|-----------:|----------:|------:|--------:|----------:|------------:|
| DefaultHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.017 ms | 0.0275 ms | 0.0294 ms | 1.008 ms | 0.9759 ms | 1.082 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 1.054 ms | 0.0207 ms | 0.0213 ms | 1.053 ms | 1.0240 ms | 1.109 ms | 1.04 | 0.03 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.046 ms | 0.0328 ms | 0.0350 ms | 1.039 ms | 0.9988 ms | 1.130 ms | 1.00 | 0.05 | 5.96 KB | 1.00 |
| DefaultHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 1.045 ms | 0.0202 ms | 0.0168 ms | 1.050 ms | 1.0154 ms | 1.074 ms | 1.00 | 0.04 | 5.96 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv4Async | Job-DZDDGH | /9.0.0/corerun | 1.394 ms | 0.0269 ms | 0.0225 ms | 1.395 ms | 1.3559 ms | 1.441 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv4Async | Job-HPXMZE | /main/corerun | 4.792 ms | 0.2019 ms | 0.2244 ms | 4.754 ms | 4.4838 ms | 5.289 ms | 3.44 | 0.17 | 6.27 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeContextIPv6Async | Job-DZDDGH | /9.0.0/corerun | 1.398 ms | 0.0273 ms | 0.0256 ms | 1.394 ms | 1.3611 ms | 1.445 ms | 1.00 | 0.02 | 10.73 KB | 1.00 |
| DefaultMutualHandshakeContextIPv6Async | Job-HPXMZE | /main/corerun | 4.716 ms | 0.0982 ms | 0.1091 ms | 4.686 ms | 4.5305 ms | 4.914 ms | 3.37 | 0.10 | 6.26 KB | 0.58 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 5.715 ms | 0.0660 ms | 0.0551 ms | 5.705 ms | 5.6337 ms | 5.832 ms | 1.00 | 0.01 | 9.66 KB | 1.00 |
| DefaultHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 5.949 ms | 0.1222 ms | 0.1358 ms | 5.960 ms | 5.7571 ms | 6.177 ms | 1.04 | 0.03 | 9.67 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 5.904 ms | 0.1713 ms | 0.1904 ms | 5.835 ms | 5.6978 ms | 6.335 ms | 1.00 | 0.04 | 9.68 KB | 1.00 |
| DefaultHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 5.862 ms | 0.1116 ms | 0.0932 ms | 5.828 ms | 5.7339 ms | 6.003 ms | 0.99 | 0.03 | 9.66 KB | 1.00 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv4Async | Job-DZDDGH | /9.0.0/corerun | 10.854 ms | 0.2105 ms | 0.1969 ms | 10.804 ms | 10.5719 ms | 11.251 ms | 1.00 | 0.02 | 17.34 KB | 1.00 |
| DefaultMutualHandshakeIPv4Async | Job-HPXMZE | /main/corerun | 11.575 ms | 0.2257 ms | 0.2001 ms | 11.556 ms | 11.2971 ms | 11.996 ms | 1.07 | 0.03 | 17.18 KB | 0.99 |
| | | | | | | | | | | | | |
| DefaultMutualHandshakeIPv6Async | Job-DZDDGH | /9.0.0/corerun | 10.850 ms | 0.2151 ms | 0.2012 ms | 10.801 ms | 10.5470 ms | 11.177 ms | 1.00 | 0.03 | 17.36 KB | 1.00 |
| DefaultMutualHandshakeIPv6Async | Job-HPXMZE | /main/corerun | 11.306 ms | 0.2226 ms | 0.2475 ms | 11.337 ms | 10.8917 ms | 11.872 ms | 1.04 | 0.03 | 15.91 KB | 0.92 |
| | | | | | | | | | | | | |
| DefaultHandshakePipeAsync | Job-DZDDGH | /9.0.0/corerun | 5.901 ms | 0.1145 ms | 0.1125 ms | 5.894 ms | 5.7267 ms | 6.163 ms | 1.00 | 0.03 | 9.96 KB | 1.00 |
| DefaultHandshakePipeAsync | Job-HPXMZE | /main/corerun | 6.032 ms | 0.1747 ms | 0.2012 ms | 6.001 ms | 5.7647 ms | 6.430 ms | 1.02 | 0.04 | 9.98 KB | 1.00 |

The main brach is main excluding this change, 9.0.0 includes this PR and #103720. Notice mainly the Context benchmarks, and the (new, PR to be raised soon) DefaultMutualHandshakeContext* benchmarks, where the new TLS resume shines. The amount of allocations is a bit weird, I might look into these later when I have time.

@rzikm

Copy link
Copy Markdown
MemberAuthor

cc @stephentoub, @ManickaP, since this might look well in your future blog posts

@stephentoub

Copy link
Copy Markdown
Member

already on my list :)

@karelzkarelz added this to the 9.0.0 milestone Jun 24, 2024
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 25, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Sep 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Net.Securitycryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.trackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support TLS Resume with client certificates on Linux

7 participants

@rzikm@wfurt@LoopedBard3@stephentoub@vcsjones@bartonjs@karelz