mirror of
https://github.com/XTLS/REALITY.git
synced 2026-10-03 04:18:03 +03:00
crypto/tls: add GetEncryptedClientHelloKeys
This allows servers to rotate their ECH keys without needing to restart the server. Fixes #71920 Change-Id: I55591ab3303d5fde639038541c50edcf1fafc9aa Reviewed-on: https://go-review.googlesource.com/c/go/+/670655 TryBot-Bypass: Roland Shoemaker <roland@golang.org> Reviewed-by: David Chase <drchase@google.com> Auto-Submit: Roland Shoemaker <roland@golang.org> Reviewed-by: Daniel McCarney <daniel@binaryparadox.net>
This commit is contained in:
@@ -851,6 +851,20 @@ type Config struct {
|
||||
// when ECH is rejected, even if set, and InsecureSkipVerify is ignored.
|
||||
EncryptedClientHelloRejectionVerify func(ConnectionState) error
|
||||
|
||||
// GetEncryptedClientHelloKeys, if not nil, is called when by a server when
|
||||
// a client attempts ECH.
|
||||
//
|
||||
// If GetEncryptedClientHelloKeys is not nil, [EncryptedClientHelloKeys] is
|
||||
// ignored.
|
||||
//
|
||||
// If GetEncryptedClientHelloKeys returns an error, the handshake will be
|
||||
// aborted and the error will be returned. Otherwise,
|
||||
// GetEncryptedClientHelloKeys must return a non-nil slice of
|
||||
// [EncryptedClientHelloKey] that represents the acceptable ECH keys.
|
||||
//
|
||||
// For further details, see [EncryptedClientHelloKeys].
|
||||
GetEncryptedClientHelloKeys func(*ClientHelloInfo) ([]EncryptedClientHelloKey, error)
|
||||
|
||||
// EncryptedClientHelloKeys are the ECH keys to use when a client
|
||||
// attempts ECH.
|
||||
//
|
||||
@@ -861,6 +875,9 @@ type Config struct {
|
||||
// will send a list of configs to retry based on the set of
|
||||
// EncryptedClientHelloKeys which have the SendAsRetry field set.
|
||||
//
|
||||
// If GetEncryptedClientHelloKeys is non-nil, EncryptedClientHelloKeys is
|
||||
// ignored.
|
||||
//
|
||||
// On the client side, this field is ignored. In order to configure ECH for
|
||||
// clients, see the EncryptedClientHelloConfigList field.
|
||||
EncryptedClientHelloKeys []EncryptedClientHelloKey
|
||||
@@ -961,6 +978,7 @@ func (c *Config) Clone() *Config {
|
||||
GetCertificate: c.GetCertificate,
|
||||
GetClientCertificate: c.GetClientCertificate,
|
||||
GetConfigForClient: c.GetConfigForClient,
|
||||
GetEncryptedClientHelloKeys: c.GetEncryptedClientHelloKeys,
|
||||
VerifyPeerCertificate: c.VerifyPeerCertificate,
|
||||
VerifyConnection: c.VerifyConnection,
|
||||
RootCAs: c.RootCAs,
|
||||
|
||||
Reference in New Issue
Block a user