From mboxrd@z Thu Jan 1 00:00:00 1970 From: David Miller Subject: Re: [PATCH net-next 0/5] tcp: Introduce a TFO key-pool for clean cookie-rotation Date: Sun, 16 Dec 2018 12:19:52 -0800 (PST) Message-ID: <20181216.121952.1167815839571774345.davem@davemloft.net> References: <20181214224007.54813-1-cpaasch@apple.com> Mime-Version: 1.0 Content-Type: Text/Plain; charset=us-ascii Content-Transfer-Encoding: 7bit Cc: netdev@vger.kernel.org, edumazet@google.com, ycheng@google.com To: cpaasch@apple.com Return-path: Received: from shards.monkeyblade.net ([23.128.96.9]:47570 "EHLO shards.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1730791AbeLPUTx (ORCPT ); Sun, 16 Dec 2018 15:19:53 -0500 In-Reply-To: <20181214224007.54813-1-cpaasch@apple.com> Sender: netdev-owner@vger.kernel.org List-ID: From: Christoph Paasch Date: Fri, 14 Dec 2018 14:40:02 -0800 > Currently, TFO only allows a single TFO-secret. This means that whenever > the secret gets changed for key-rotation purposes, all the previously > issued TFO-cookies become invalid. This means that clients will fallback > to "regular" TCP, incurring a cost of one additional round-trip. > > This patchset introduces a TFO key-pool that allows to more gracefully > change the key. The size of the pool is 2 (this could be changed in the > future through a sysctl if needed). When a client connects with an "old" > TFO cookie, the server will now accept the data in the SYN and at the > same time announce a new TFO-cookie to the client. > > We have seen a significant reduction of LINUX_MIB_TCPFASTOPENPASSIVEFAIL > thanks to these patches. Invalid cookies are now solely observed when > clients behind a NAT are getting a new public IP. Yuchung and Eric, please review.