diff --git a/src/xprt_quic.c b/src/xprt_quic.c index 08c4ad11a..55c45f964 100644 --- a/src/xprt_quic.c +++ b/src/xprt_quic.c @@ -1184,7 +1184,7 @@ int ssl_quic_initial_ctx(struct bind_conf *bind_conf) #elif (HA_OPENSSL_VERSION_NUMBER >= 0x10101000L) if (bind_conf->ssl_conf.early_data) { SSL_CTX_set_options(ctx, SSL_OP_NO_ANTI_REPLAY); - SSL_CTX_set_max_early_data(ctx, global.tune.bufsize - global.tune.maxrewrite); + SSL_CTX_set_max_early_data(ctx, 0xffffffff); } SSL_CTX_set_client_hello_cb(ctx, ssl_sock_switchctx_cbk, NULL); SSL_CTX_set_tlsext_servername_callback(ctx, ssl_sock_switchctx_err_cbk); @@ -5075,6 +5075,10 @@ static int qc_conn_init(struct connection *conn, void **xprt_ctx) qc->enc_params, qc->enc_params_len) == -1) goto err; + /* Enabling 0-RTT */ + if (bc->ssl_conf.early_data) + SSL_set_quic_early_data_enabled(ctx->ssl, 1); + SSL_set_accept_state(ctx->ssl); }