diff --git a/common.go b/common.go index dc4adae..9ea149a 100644 --- a/common.go +++ b/common.go @@ -597,10 +597,13 @@ type Config struct { LimitFallbackUpload LimitFallback LimitFallbackDownload LimitFallback - // Rand provides the source of entropy for nonces and RSA blinding. + // Rand provides the source of entropy for the connection. // If Rand is nil, TLS uses the cryptographic random reader in package - // crypto/rand. - // The Reader must be safe for use by multiple goroutines. + // crypto/rand. The Reader must be safe for use by multiple goroutines. + // + // Deprecated: this should be left nil in production. Not all TLS + // configurations are guaranteed to use Rand. Test code can use + // [testing/cryptotest.SetGlobalRandom] instead. Rand io.Reader // Time returns the current time as the number of seconds since the epoch.