
4/3/2023 · Rushil Mehra
What this post added
This post details a vulnerability discovered in Cloudflare's mTLS implementation where revoked client certificates were not being blocked during TLS session resumption. The issue stemmed from the client certificate chain not being re-evaluated after a session was resumed, leading to a bypass of Firewall Rules. The immediate mitigation involved disabling session resumption for mTLS connections, followed by a permanent fix that ensures the client certificate serial number and issuer SKI are correctly accessed and checked for revocation status even during session resumption.