Skip to content

ts_tunnel: verify forward secrecy for idle sessions #344

Description

@danderson

The audit found that we weren't expiring idle sessions properly, which is a forward secrecy risk. We happened to implement proper expiry of idle sessions during the audit (a4c5b52 and e77c211), so in theory that finding is already remediated.

However, I'm filing this to go and re-check the detailed finding description against what we implemented, and verify that we didn't miss anything.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions