Skip to content

Commit

Permalink
https: reuse TLS sessions in Agent
Browse files Browse the repository at this point in the history
Fix: #1499
PR-URL: #2228
Reviewed-By: Shigeki Ohtsu <ohtsu@iij.ad.jp>
Reviewed-By: Trevor Norris <trev.norris@gmail.com>
  • Loading branch information
indutny committed Jul 27, 2015
1 parent 4e78cd7 commit 2ca5a3d
Show file tree
Hide file tree
Showing 4 changed files with 193 additions and 2 deletions.
1 change: 1 addition & 0 deletions lib/_http_agent.js
Original file line number Diff line number Diff line change
Expand Up @@ -171,6 +171,7 @@ Agent.prototype.createSocket = function(req, options) {
}

var name = self.getName(options);
options._agentKey = name;

debug('createConnection', name, options);
options.encoding = null;
Expand Down
14 changes: 13 additions & 1 deletion lib/_tls_wrap.js
Original file line number Diff line number Diff line change
Expand Up @@ -584,6 +584,17 @@ TLSSocket.prototype._start = function() {
this._handle.start();
};

TLSSocket.prototype._isSessionResumed = function _isSessionResumed(session) {
if (!session)
return false;

var next = this.getSession();
if (!next)
return false;

return next.equals(session);
};

TLSSocket.prototype.setServername = function(name) {
this._handle.setServername(name);
};
Expand Down Expand Up @@ -999,7 +1010,8 @@ exports.connect = function(/* [port, host], options, cb */) {
var verifyError = socket._handle.verifyError();

// Verify that server's identity matches it's certificate's names
if (!verifyError) {
// Unless server has resumed our existing session
if (!verifyError && !socket._isSessionResumed(options.session)) {
var cert = socket.getPeerCertificate();
verifyError = options.checkServerIdentity(hostname, cert);
}
Expand Down
50 changes: 49 additions & 1 deletion lib/https.js
Original file line number Diff line number Diff line change
Expand Up @@ -58,14 +58,40 @@ function createConnection(port, host, options) {
}

debug('createConnection', options);
return tls.connect(options);

if (options._agentKey) {
const session = this._getSession(options._agentKey);
if (session) {
debug('reuse session for %j', options._agentKey);
options = util._extend({
session: session
}, options);
}
}

const self = this;
const socket = tls.connect(options, function() {
if (!options._agentKey)
return;

self._cacheSession(options._agentKey, socket.getSession());
});
return socket;
}


function Agent(options) {
http.Agent.call(this, options);
this.defaultPort = 443;
this.protocol = 'https:';
this.maxCachedSessions = this.options.maxCachedSessions;
if (this.maxCachedSessions === undefined)
this.maxCachedSessions = 100;

this._sessionCache = {
map: {},
list: []
};
}
inherits(Agent, http.Agent);
Agent.prototype.createConnection = createConnection;
Expand Down Expand Up @@ -100,6 +126,28 @@ Agent.prototype.getName = function(options) {
return name;
};

Agent.prototype._getSession = function _getSession(key) {
return this._sessionCache.map[key];
};

Agent.prototype._cacheSession = function _cacheSession(key, session) {
// Fast case - update existing entry
if (this._sessionCache.map[key]) {
this._sessionCache.map[key] = session;
return;
}

// Put new entry
if (this._sessionCache.list.length >= this.maxCachedSessions) {
const oldKey = this._sessionCache.list.shift();
debug('evicting %j', oldKey);
delete this._sessionCache.map[oldKey];
}

this._sessionCache.list.push(key);
this._sessionCache.map[key] = session;
};

const globalAgent = new Agent();

exports.globalAgent = globalAgent;
Expand Down
130 changes: 130 additions & 0 deletions test/parallel/test-https-agent-session-reuse.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,130 @@
'use strict';
var common = require('../common');
var assert = require('assert');

if (!common.hasCrypto) {
console.log('1..0 # Skipped: missing crypto');
return;
}

var https = require('https');
var crypto = require('crypto');

var fs = require('fs');

var options = {
key: fs.readFileSync(common.fixturesDir + '/keys/agent1-key.pem'),
cert: fs.readFileSync(common.fixturesDir + '/keys/agent1-cert.pem')
};

var ca = fs.readFileSync(common.fixturesDir + '/keys/ca1-cert.pem');

var clientSessions = {};
var serverRequests = 0;

var agent = new https.Agent({
maxCachedSessions: 1
});

var server = https.createServer(options, function(req, res) {
if (req.url === '/drop-key')
server.setTicketKeys(crypto.randomBytes(48));

serverRequests++;
res.end('ok');
}).listen(common.PORT, function() {
var queue = [
{
name: 'first',

method: 'GET',
path: '/',
servername: 'agent1',
ca: ca,
port: common.PORT
},
{
name: 'first-reuse',

method: 'GET',
path: '/',
servername: 'agent1',
ca: ca,
port: common.PORT
},
{
name: 'cipher-change',

method: 'GET',
path: '/',
servername: 'agent1',

// Choose different cipher to use different cache entry
ciphers: 'AES256-SHA',
ca: ca,
port: common.PORT
},
// Change the ticket key to ensure session is updated in cache
{
name: 'before-drop',

method: 'GET',
path: '/drop-key',
servername: 'agent1',
ca: ca,
port: common.PORT
},

// Ticket will be updated starting from this
{
name: 'after-drop',

method: 'GET',
path: '/',
servername: 'agent1',
ca: ca,
port: common.PORT
},
{
name: 'after-drop-reuse',

method: 'GET',
path: '/',
servername: 'agent1',
ca: ca,
port: common.PORT
}
];

function request() {
var options = queue.shift();
options.agent = agent;
https.request(options, function(res) {
clientSessions[options.name] = res.socket.getSession();

res.resume();
res.on('end', function() {
if (queue.length !== 0)
return request();
server.close();
});
}).end();
}
request();
});

process.on('exit', function() {
assert.equal(serverRequests, 6);
assert.equal(clientSessions['first'].toString('hex'),
clientSessions['first-reuse'].toString('hex'));
assert.notEqual(clientSessions['first'].toString('hex'),
clientSessions['cipher-change'].toString('hex'));
assert.notEqual(clientSessions['first'].toString('hex'),
clientSessions['before-drop'].toString('hex'));
assert.notEqual(clientSessions['cipher-change'].toString('hex'),
clientSessions['before-drop'].toString('hex'));
assert.notEqual(clientSessions['before-drop'].toString('hex'),
clientSessions['after-drop'].toString('hex'));
assert.equal(clientSessions['after-drop'].toString('hex'),
clientSessions['after-drop-reuse'].toString('hex'));
});

0 comments on commit 2ca5a3d

Please sign in to comment.