TLS 1.3 0-RTT: check replay safety before optimizing latency
Evaluate handshake latency together with replay safety for payments, claims and write operations.
Contents of this article
Earlier delivery does not make repetition safe
TLS 1.3 specifies replay considerations for 0-RTT data. Accepting early data is a concern for both the edge and the application; HTTPS alone does not make every write operation suitable for it.
Classify endpoints by business effect
Public reads, account lookups, order creation and benefit claims have different consequences when repeated. Check state changes, idempotency, duplicate detection and consistency rather than relying only on the HTTP method name.
Confirm support at each hop
Client-to-edge and edge-to-origin connections may use different settings. Confirm support, disablement and fallback on each hop. This protocol discussion does not state that any WAFPRO plan enables 0-RTT by default.
Measure correctness as well as speed
Test first connections, resumed sessions and network retries. Record both latency and how many times the operation executes. Fix duplicate writes before pursuing a faster handshake configuration.
