Behavior of TLS session cache release when custom root certificates are supplied via --allow-net
0 reputation · 10 Dec 2023, 06:05 UTC
When running a Deno HTTP server with the --allow-net flag and providing custom root certificates, it is unclear whether Deno actively releases or reuses TLS session caches after connections close.
The goal is to determine if the TLS session cache is retained for the lifetime of the process, flushed periodically, or tied to the lifecycle of individual sockets, especially under long‑running workloads that rotate certificates.
Constraints include the reliance on the Rustls crate used by Deno, potential changes in its session‑ticket handling, and the lack of explicit documentation on cache‑eviction policies for custom CAs.
Does Deno expose any API or runtime flag to inspect or force TLS session cache cleanup?
How does the cache behave when the same custom CA is re‑loaded or replaced during execution?
Is there a measurable impact on memory usage if the cache is allowed to grow unchecked?