envoyproxy/envoy
Voir sur GitHubSPIFFE validator + "mtls_authenticated" do not support session resumption
Open
#42 668 ouverte le 17 déc. 2025
area/tlsbughelp wanted
Métriques du dépôt
- Stars
- (27 997 stars)
- Métriques de merge PR
- (Merge moyen 7j 21h) (260 PRs mergées en 30 j)
Description
On a resumed session, "peer certificate validated" is set to false since that bit is cert by the validator flow per connection. That means any policy using mtls_authenticated evaluates to false, and can be dangerous if used as a DENY policy. The workaround is to disable session resumption in TLS.