mirror of
https://github.com/XTLS/REALITY.git
synced 2026-10-06 05:48:00 +03:00
crypto/tls: add GetEncryptedClientHelloKeys
This allows servers to rotate their ECH keys without needing to restart the server. Fixes #71920 Change-Id: I55591ab3303d5fde639038541c50edcf1fafc9aa Reviewed-on: https://go-review.googlesource.com/c/go/+/670655 TryBot-Bypass: Roland Shoemaker <roland@golang.org> Reviewed-by: David Chase <drchase@google.com> Auto-Submit: Roland Shoemaker <roland@golang.org> Reviewed-by: Daniel McCarney <daniel@binaryparadox.net>
This commit is contained in:
+9
-1
@@ -150,7 +150,15 @@ func (c *Conn) readClientHello(ctx context.Context) (*clientHelloMsg, *echServer
|
||||
// the contents of the client hello, since we may swap it out completely.
|
||||
var ech *echServerContext
|
||||
if len(clientHello.encryptedClientHello) != 0 {
|
||||
clientHello, ech, err = c.processECHClientHello(clientHello)
|
||||
echKeys := c.config.EncryptedClientHelloKeys
|
||||
if c.config.GetEncryptedClientHelloKeys != nil {
|
||||
echKeys, err = c.config.GetEncryptedClientHelloKeys(clientHelloInfo(ctx, c, clientHello))
|
||||
if err != nil {
|
||||
c.sendAlert(alertInternalError)
|
||||
return nil, nil, err
|
||||
}
|
||||
}
|
||||
clientHello, ech, err = c.processECHClientHello(clientHello, echKeys)
|
||||
if err != nil {
|
||||
return nil, nil, err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user