How to use this reference
Document which authenticated identities and policy decisions must survive connection resumption in an owned hosting design. Review library contracts and remediation evidence for preserved identity context rather than assuming that an accepted session ticket establishes all application authority.
Before reading
- TLS certificates and session resumption
- Virtual hosting and application routing
Context and limits
- Measurements and vendor observations are historical, not evidence of present exposure.
- The study describes sampling and configuration limits; its findings are not exhaustive.
- This record summarizes identity invariants and countermeasures, not the paper’s testing procedures.
Sources and provenance
- STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets USENIX Association · reviewed 2026-10-03
- Publisher-hosted proceedings paper USENIX Association · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.