1. Specific mode for verifying peer certificate
- Current 'mode' for verifying peer certificate is global, it's good to have specific mode among different sites hosted on a same machine. This mode will be preferred if it is not NULL. Otherwise, global mode will take effect.
2. Optimization on TLS record size
- The client can decipher the data only once it has received a full record over SSL. The record size can have significant impact on the page load time performance of the application. No limitation on record size means that clients might have to download up to 16KB of data before starting to process them, whereas very small records incur a larger overhead due to record framing. The suggestion is to configure the TLS record size to fit into a single TCP segment, this can improve page load times on browsers located over high latency or low bandwidth networks.
- Status: https://issues.apache.org/jira/browse/TS-2365

3. Configurable session time
- Session size is configurable, whereas application can not specify a session time out threshold. The default is 300 seconds. In some cases, applications need to reduce or increase the caching time, it's good to be configurable.
4. Expose API to extract peer certificate data
- Application use ATS to verify peer certificate, and expect some specific cert data (i.e. subject, issuer info) can be forwarded to orgin servers as well. It's better to expose API to extract peer certificate data.
- Status: https://issues.apache.org/jira/browse/TS-2210

5. SSL_read size threshold
- A few customers in Yahoo expect a size threshold for client request over ssl from protecting their system perspective. If the max reqested data exceed the threshold, server will reject the client connection.