mirror of
https://github.com/XTLS/REALITY.git
synced 2026-09-29 10:27:55 +03:00
crypto/internal/hpke: modularize API and support more ciphersuites
Updates #75300 Change-Id: I6a6a6964de449b36bc6f5594e08c3c47a0a2f17f Reviewed-on: https://go-review.googlesource.com/c/go/+/701435 Reviewed-by: Daniel McCarney <daniel@binaryparadox.net> LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Auto-Submit: Filippo Valsorda <filippo@golang.org> Reviewed-by: Mark Freeman <markfreeman@google.com> Reviewed-by: Junyang Shao <shaojunyang@google.com>
This commit is contained in:
@@ -914,13 +914,29 @@ type Config struct {
|
||||
// with a specific ECH config known to a client.
|
||||
type EncryptedClientHelloKey struct {
|
||||
// Config should be a marshalled ECHConfig associated with PrivateKey. This
|
||||
// must match the config provided to clients byte-for-byte. The config
|
||||
// should only specify the DHKEM(X25519, HKDF-SHA256) KEM ID (0x0020), the
|
||||
// HKDF-SHA256 KDF ID (0x0001), and a subset of the following AEAD IDs:
|
||||
// AES-128-GCM (0x0001), AES-256-GCM (0x0002), ChaCha20Poly1305 (0x0003).
|
||||
// must match the config provided to clients byte-for-byte. The config must
|
||||
// use as KEM one of
|
||||
//
|
||||
// - DHKEM(P-256, HKDF-SHA256) (0x0010)
|
||||
// - DHKEM(P-384, HKDF-SHA384) (0x0011)
|
||||
// - DHKEM(P-521, HKDF-SHA512) (0x0012)
|
||||
// - DHKEM(X25519, HKDF-SHA256) (0x0020)
|
||||
//
|
||||
// and as KDF one of
|
||||
//
|
||||
// - HKDF-SHA256 (0x0001)
|
||||
// - HKDF-SHA384 (0x0002)
|
||||
// - HKDF-SHA512 (0x0003)
|
||||
//
|
||||
// and as AEAD one of
|
||||
//
|
||||
// - AES-128-GCM (0x0001)
|
||||
// - AES-256-GCM (0x0002)
|
||||
// - ChaCha20Poly1305 (0x0003)
|
||||
//
|
||||
Config []byte
|
||||
// PrivateKey should be a marshalled private key. Currently, we expect
|
||||
// this to be the output of [ecdh.PrivateKey.Bytes].
|
||||
// PrivateKey should be a marshalled private key, in the format expected by
|
||||
// HPKE's DeserializePrivateKey (see RFC 9180), for the KEM used in Config.
|
||||
PrivateKey []byte
|
||||
// SendAsRetry indicates if Config should be sent as part of the list of
|
||||
// retry configs when ECH is requested by the client but rejected by the
|
||||
|
||||
Reference in New Issue
Block a user