Re: SSL session import/export
Bastian Jesuiter via curl-users <[email protected]> Fri, 31 Jul 2026 11:38:56 +0200
| Newsgroups | gmane.comp.web.curl.general |
|---|---|
| Message-ID | <CAL07qPUt6Meo+Sgsc5-s0vK6eo1=MdAgfJBw3n_M=ZoQDngpSA@mail.gmail.com> |
--===============1843220408566524469== Content-Type: multipart/alternative; boundary="000000000000c59be20657e4f5a3" --000000000000c59be20657e4f5a3 Content-Type: text/plain; charset="UTF-8" Hi, Yeah that is most likely. There are not a lot of tools and web servers that actually offer http3. Browsers do support it, but on the server side, basically only Google and a few others actually offer http3 connections. And those are usually not the targets that will be accessed by curl. I would've loved to test http3 by now, but in typescript, bun seems to be the one of the first to offer experimental http3 for the server side. Language http clients (Java, C(*)) often times do also not include http3, so having a server that accepts http3 is rather pointless. It seems that there's not really an incentive for now to actually provide http3 connections on both client and server side. Even nginx h3 module is considered experimental and not included by default but must be added manually. I think there just won't be a lot of real use case targets to test curl with. Especially in internal networks. Although I'll probably try to experiment with it, when bun 1.4 releases with experimental http3 support. Bastian On Fri, 31 Jul 2026, 10:47 Daniel Stenberg via curl-users, < [email protected]> wrote: > Hello friends, > > I would like us to move SSL session import/export out of experimental > status > before end of year 2026. > > Import/Export of SSL sessions tickets in libcurl and curl command line > option > '--ssl-session ' is a feature provided for faster TLS handshakes and use > of > TLSv1.3/QUIC Early Data (0-RTT). > > We basically hear nothing from user about these features that have already > been provided for a while (since January 2025). My feeling is that we > won't > hear anything further either until we ship this "for real". > > Thoughts? > > -- > > / daniel.haxx.se || https://rock-solid.curl.dev > -- > Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users > Etiquette: https://curl.se/mail/etiquette.html > --000000000000c59be20657e4f5a3 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">Hi,=C2=A0<div dir=3D"auto"><br></div><div dir=3D"auto">Ye= ah that is most likely.=C2=A0</div><div dir=3D"auto"><br></div><div dir=3D"= auto">There are not a lot of tools and web servers that actually offer http= 3.=C2=A0</div><div dir=3D"auto"><br></div><div dir=3D"auto">Browsers do sup= port it, but on the server=C2=A0side, basically only Google and a few other= s actually offer http3 connections. And those are usually not the targets t= hat will be accessed by curl.=C2=A0</div><div dir=3D"auto"><br></div><div d= ir=3D"auto">I would've loved to test http3 by now, but in typescript, b= un seems to be the one of the first to offer experimental http3 for the ser= ver side. Language http clients (Java, C(*)) often times do also not includ= e http3, so having a server that accepts http3 is rather pointless. It seem= s that there's not really an incentive for now to actually provide http= 3 connections on both client and server side.=C2=A0</div><div dir=3D"auto">= <br></div><div dir=3D"auto">Even nginx h3 module is considered experimental= and not included by default but must be added manually.=C2=A0</div><div di= r=3D"auto"><br></div><div dir=3D"auto">I think there just won't be a lo= t of real use case targets to test curl with. Especially in internal networ= ks.=C2=A0 Although I'll probably try to experiment with it, when bun 1.= 4 releases with experimental http3 support.=C2=A0</div><div dir=3D"auto"><b= r></div><div dir=3D"auto">Bastian</div><div dir=3D"auto"><br></div></div><b= r><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class= =3D"gmail_attr">On Fri, 31 Jul 2026, 10:47 Daniel Stenberg via curl-users, = <<a href=3D"mailto:[email protected]">[email protected]</a= >> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0= 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hello friends,<br> <br> I would like us to move SSL session import/export out of experimental statu= s <br> before end of year 2026.<br> <br> Import/Export of SSL sessions tickets in libcurl and curl command line opti= on <br> '--ssl-session ' is a feature provided for faster TLS handshakes an= d use of <br> TLSv1.3/QUIC Early Data (0-RTT).<br> <br> We basically hear nothing from user about these features that have already = <br> been provided for a while (since January 2025). My feeling is that we won&#= 39;t <br> hear anything further either until we ship this "for real".<br> <br> Thoughts?<br> <br> -- <br> <br> =C2=A0 / <a href=3D"http://daniel.haxx.se" rel=3D"noreferrer noreferrer" ta= rget=3D"_blank">daniel.haxx.se</a> || <a href=3D"https://rock-solid.curl.de= v" rel=3D"noreferrer noreferrer" target=3D"_blank">https://rock-solid.curl.= dev</a><br> -- <br> Unsubscribe: <a href=3D"https://lists.haxx.se/mailman/listinfo/curl-users" = rel=3D"noreferrer noreferrer" target=3D"_blank">https://lists.haxx.se/mailm= an/listinfo/curl-users</a><br> Etiquette:=C2=A0 =C2=A0<a href=3D"https://curl.se/mail/etiquette.html" rel= =3D"noreferrer noreferrer" target=3D"_blank">https://curl.se/mail/etiquette= .html</a><br> </blockquote></div> --000000000000c59be20657e4f5a3-- --===============1843220408566524469== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users Etiquette: https://curl.se/mail/etiquette.html --===============1843220408566524469==--