4 ms·
I'm also pretty happy about what landed in the cryptography packages. Session ticket keys, which are a major weak link in Forward Secrecy in TLS 1.0-1.2 [0], a
by FiloSottile 6y ago
I'm also pretty happy about what landed in the cryptography packages.
Session ticket keys, which are a major weak link in Forward Secrecy in TLS 1.0-1.2 [0], are now rotated automatically every day, and dropped after 7 days [1]. Session keys are also dropped once they get too old [2], instead of becoming an increasingly powerful Forward Secrecy liability.
The tls.Config.VerifyConnection callback is a much more powerful and usable way to customize peer verification [3].
X.509 root CAs are now extracted on macOS by linking directly against Security.framework with some assembly glue, instead of using cgo [4]. (Warning: awakens Cthulhu.)
crypto/x509 now ignores the 20-year-deprecated Common Name field by default [5] and has a consistent rule about invalid hostnames [6].
crypto/elliptic now provides MarshalCompressed and UnmarshalCompressed for compressed point encodings [7].
The clever TLS 1.3 downgrade canary in the server random is now enforced client side [8].
PrivateKey and PublicKey types implement Equal, giving a consistent method to build type-safe interfaces for them [9].
math/big has a new Int.FillBytes method for fixed size, zero allocation byte serialization [9], which we used all over the crypto packages.
RevocationList and CreateRevocationList were added to crypto/x509 to generate spec compliant CRLs [11].
crypto/ecdsa has two new functions, SignASN1 and VerifyASN1 that operate on encoded signatures instead of big.Ints that everyone was encoding/decoding anyway [12].
Plus some performance, cosmetic, correctness, and documentation improvements! Not a bad cycle overall, even if it made sense to focus on smaller scope tasks for a while.
[0]: https://blog.filippo.io/we-need-to-talk-about-session-tickets/ https://blog.filippo.io/we-need-to-talk-about-session-ticket...
[1]: https://go.googlesource.com/go/+/43f2f5024b https://go.googlesource.com/go/+/43f2f5024b
[2]: https://go.googlesource.com/go/+/6ea19bb668 https://go.googlesource.com/go/+/6ea19bb668
[3]: https://go.googlesource.com/go/+/62a3f2e27c https://go.googlesource.com/go/+/62a3f2e27c
[4]: https://go.googlesource.com/go/+/6f52790a20 https://go.googlesource.com/go/+/6f52790a20
[5]: https://go.googlesource.com/go/+/d65e1b2e41 https://go.googlesource.com/go/+/d65e1b2e41
[6]: https://go.googlesource.com/go/+/9d1e120c42 https://go.googlesource.com/go/+/9d1e120c42
[7]: https://go.googlesource.com/go/+/5c13cab36b https://go.googlesource.com/go/+/5c13cab36b
[8]: https://go.googlesource.com/go/+/a6c6e59655 https://go.googlesource.com/go/+/a6c6e59655
[9]: https://go.googlesource.com/go/+/b5f2c0f502 https://go.googlesource.com/go/+/b5f2c0f502
[10]: https://go.googlesource.com/go/+/c9d5f60eaa https://go.googlesource.com/go/+/c9d5f60eaa
[11]: https://go.googlesource.com/go/+/5d47f870a6 https://go.googlesource.com/go/+/5d47f870a6
[12]: https://go.googlesource.com/go/+/8c09e8af36 https://go.googlesource.com/go/+/8c09e8af36
- mholt 6y ago> Session ticket keys, which are a major weak link in Forward Secrecy in TLS 1.0-1.2, are now rotated automatically every day, and dropped after 7 days. Wooooah, that's awesome! Up to now I think only Caddy has been doing this automatically & by default, I'm happy to see the std lib able to offer this too. Maybe we can simplify some of our code base. (Although, on second thought, Caddy can rotate the keys distributed across a cluster so as to improve TLS performance behind load balancers, for example; so we might still need to use our own home-brewed rotation. Which is fine!) > The tls.Config.VerifyConnection callback is a much more powerful and usable way to customize peer verification [3]. Also looking forward to using this in Caddy! Right now we use VerifyPeerCertificate which is... fine, and definitely better than without it, but I am sure plenty of users will be happy to have the extra flexibility and added robustness of VerifyConnection. Everything else looks stellar too -- keep up the good work!
- benhoyt 6y agoThanks! As a service/app developer, I'm not familiar with a lot of that terminology, but I'm very thankful that someone on the Go team is.
- nemo1618 6y ago(Int).FillBytes is great, thanks! I had resorted to using Bits and reimplementing the Bytes logic on top of that...not pretty.