diff --git a/ech.go b/ech.go index c19ff76..d88a138 100644 --- a/ech.go +++ b/ech.go @@ -184,6 +184,11 @@ func pickECHConfig(list []EchConfig) (*EchConfig, hpke.PublicKey, hpke.KDF, hpke if err != nil { continue } + // 0xFFFF is an export-only AEAD that cannot seal/open, making + // it an invalid choice for encrypting ClientHelloInner. + if cs.AEADID == 0xFFFF { + continue + } aead, err := hpke.NewAEAD(cs.AEADID) if err != nil { continue