So currently, I am writing my own web server which is using the openssl library (most recent version from 2022/07/05).
While initializing the openssl library I specify TLS 1.3 as the minimum version with SSL_CTX_set_min_proto_version( sslctx, TLS1_3_VERSION );
The client accept logic, simplified, looks the following:
SSL_new()
SSL_set_fd()
SSL_accept()
Error checking with the SSL_accept() return value
SSL_read()
SSL_write()
SSL_shutdown()
SSL_free()
close()
Everything works fine so far, I can locally connect with my Firefox-browser (102.0 - 64 bit and Kubuntu 22.04 - 64 bit).
The problem now begins, when I press and keep pressing the F5 key to spam refresh for the current page/resource.
When I am doing that, the error check catches the following error:
error:0A000126:SSL routines::unexpected eof while reading.
The openssl docu for the SSL_shutdown function states that there are implementations that do not send the required close_notify alert and therefore the error can be suppressed by adding SSL_OP_IGNORE_UNEXPECTED_EOF as a flag when setting the flags with SSL_CTX_set_options() during initialization.
Even though, I don't think Firefox is not sending the close_notify, but I guess just not in case after sending x amount of requests?
Is it safe to suppress that error message or do I miss something else which I need to implement to catch when someone is spamming refresh button?