[tls] Treat session secret as "resumption master secret"

When resuming a session in TLS versions 1.2 and earlier, the master
secret is simply reused.  The value stored in the session is therefore
the same as the master secret used in the connection.

For TLS version 1.3, there is a separate concept of a "resumption
master secret" that is derived from the original connection's master
secret, and from which the resumed connection's new master secret will
be derived.

Rename the session master_secret to resumption_master_secret to
clarify this separation.

Resume use of the master secret (i.e. copy the secret from the session
to the connection) only after the cipher suite has been selected, to
reduce differences with the expected flow for TLS version 1.3.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
2 files changed
tree: c99419b7791bb9e964803566a83235c332cd24b1
  1. .github/
  2. contrib/
  3. src/
  4. CHANGELOG.md
  5. CONTRIBUTING.md
  6. COPYING
  7. COPYING.GPLv2
  8. COPYING.UBDL
  9. README.md
  10. RELEASE.md
  11. RELNOTES.tmpl.md
README.md

iPXE network bootloader

Build Coverity Release

iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:

  • boot from a web server via HTTP or HTTPS,

  • boot from an iSCSI, FCoE, or AoE SAN,

  • control the boot process with a script,

  • create interactive forms and menus.

You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.

iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).

You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.

For full documentation, visit the iPXE website.