
The Cloudflare mTLS vulnerability - A Deep Dive Analysis
The Backend Engineering Show with Hussein Nasser
00:00
How to Safely Re-Enable Resumption for MTLs
If you run into that code path where it says, okay, I'm assuming a session and this the new session tickets is good, then go through this code path and do something else. Almost the same thing, but we're skipping a bunch of code. But that code path, they did not add this code to actually store the client certificate in the TLS connection. What does that mean? Now we have a TLS connection with an empty client certificate. And if you have an empty client Certificate, nothing is getting sent to the server to the back in upstream servers. The request will only have empty client certificates. So what does the client do? The client, this upstream server
Transcript
Play full episode
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.