Re: [PATCH v2 net-next] tcp: Enable TFO without a cookie on a per-socket basis

2017-10-23 Thread Christoph Paasch
Hello, On 20/10/17 - 17:46:06, Yuchung Cheng wrote: > On Fri, Oct 20, 2017 at 2:13 PM, Christoph Paasch wrote: > > > > We already allow to enable TFO without a cookie by using the > > fastopen-sysctl and setting it to TFO_SERVER_COOKIE_NOT_REQD (0x200). > > This is safe to do in certain environme

Re: [PATCH v2 net-next] tcp: Enable TFO without a cookie on a per-socket basis

2017-10-20 Thread Yuchung Cheng
On Fri, Oct 20, 2017 at 2:13 PM, Christoph Paasch wrote: > > We already allow to enable TFO without a cookie by using the > fastopen-sysctl and setting it to TFO_SERVER_COOKIE_NOT_REQD (0x200). > This is safe to do in certain environments where we know that there > isn't a malicous host (aka., dat

[PATCH v2 net-next] tcp: Enable TFO without a cookie on a per-socket basis

2017-10-20 Thread Christoph Paasch
We already allow to enable TFO without a cookie by using the fastopen-sysctl and setting it to TFO_SERVER_COOKIE_NOT_REQD (0x200). This is safe to do in certain environments where we know that there isn't a malicous host (aka., data-centers). A server however might be talking to both sides (public