diff --git a/common.go b/common.go index 074c988..8f357da 100644 --- a/common.go +++ b/common.go @@ -1880,3 +1880,16 @@ func fipsAllowChain(chain []*x509.Certificate) bool { return true } + +// anyUnexpiredChain reports if at least one of verifiedChains is still +// unexpired. If verifiedChains is empty, it returns false. +func anyUnexpiredChain(verifiedChains [][]*x509.Certificate, now time.Time) bool { + for _, chain := range verifiedChains { + if len(chain) != 0 && !slices.ContainsFunc(chain, func(cert *x509.Certificate) bool { + return now.Before(cert.NotBefore) || now.After(cert.NotAfter) // cert is expired + }) { + return true + } + } + return false +} diff --git a/handshake_client.go b/handshake_client.go index 1c8b931..bb2f8eb 100644 --- a/handshake_client.go +++ b/handshake_client.go @@ -399,9 +399,6 @@ func (c *Conn) loadSession(hello *clientHelloMsg) ( return nil, nil, nil, nil } - // Check that the cached server certificate is not expired, and that it's - // valid for the ServerName. This should be ensured by the cache key, but - // protect the application from a faulty ClientSessionCache implementation. if c.config.time().After(session.peerCertificates[0].NotAfter) { // Expired certificate, delete the entry. c.config.ClientSessionCache.Put(cacheKey, nil) @@ -413,6 +410,13 @@ func (c *Conn) loadSession(hello *clientHelloMsg) ( return nil, nil, nil, nil } if err := session.peerCertificates[0].VerifyHostname(c.config.ServerName); err != nil { + // This should be ensured by the cache key, but protect the + // application from a faulty ClientSessionCache implementation. + return nil, nil, nil, nil + } + if !anyUnexpiredChain(session.verifiedChains, c.config.time()) { + // No valid chains, delete the entry. + c.config.ClientSessionCache.Put(cacheKey, nil) return nil, nil, nil, nil } } diff --git a/handshake_server.go b/handshake_server.go index 8ec3e34..3c8a571 100644 --- a/handshake_server.go +++ b/handshake_server.go @@ -511,7 +511,7 @@ func (hs *serverHandshakeState) checkForResumption() error { return nil } if sessionHasClientCerts && c.config.ClientAuth >= VerifyClientCertIfGiven && - len(sessionState.verifiedChains) == 0 { + !anyUnexpiredChain(sessionState.verifiedChains, c.config.time()) { return nil } diff --git a/handshake_server_tls13.go b/handshake_server_tls13.go index ff28fe2..d4f9ef8 100644 --- a/handshake_server_tls13.go +++ b/handshake_server_tls13.go @@ -465,7 +465,7 @@ func (hs *serverHandshakeStateTLS13) checkForResumption() error { continue } if sessionHasClientCerts && c.config.ClientAuth >= VerifyClientCertIfGiven && - len(sessionState.verifiedChains) == 0 { + !anyUnexpiredChain(sessionState.verifiedChains, c.config.time()) { continue }