Log negotiated TLS groups for HKEX adoption - #8454
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Add test coverage verifying the emitted hybrid_key_exchange telemetry.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds INFO-level inbound TLS handshake telemetry for negotiated groups, hybrid key exchange classification, and connection correlation.
Changes:
- Logs the negotiated TLS group and connection ID.
- Adds machine-readable
hybrid_key_exchangestatus. - Retains fallback handling for unknown groups.
| File | Summary |
|---|---|
src/tls/openssl_server.h |
Logs negotiated TLS metadata after successful handshakes. |
The new telemetry lacks test assertions for hybrid and classical classifications.
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
The code needs formatting |
|
A problem with doing this on handshake every time is that it's a log line even if the handshake fails, and so a client doing lots of failed handshakes for whatever reason will spam the log. |
The changes added only logs at INFO when SSL_accept() returns 1, so failed handshakes and retries won’t emit it. One issue still remains where a lot of successful connections can still generate log volume. |

Summary
Validation
Full test execution was not available because the WSL environment does not have Cargo installed.