NewSessionTicket (Post-Handshake)
Server sends after Finished:
struct {
uint32 ticket_lifetime; // seconds until ticket expires
uint32 ticket_age_add; // random value to obfuscate age
opaque ticket_nonce<0..255>;
opaque ticket<1..2^16-1>; // opaque blob (encrypted by server)
Extension extensions<0..2^16-2>;
} NewSessionTicket;
The PSK value derived from the ticket:
PSK = HKDF-Expand-Label(resumption_master_secret, "resumption",
ticket_nonce, Hash.length)