mirror of
https://github.com/XTLS/Xray-docs-next.git
synced 2026-10-08 22:59:54 +03:00
Xray-core: Forbid unencrypted outbounds on public Internet for VLESS and Trojan; Remove "none/zero/plain" for VMess and Shadowsocks
This commit is contained in:
@@ -14,7 +14,6 @@ Current compatibility is as follows:
|
||||
- aes-128-gcm
|
||||
- chacha20-poly1305 (or chacha20-ietf-poly1305)
|
||||
- xchacha20-poly1305 (or xchacha20-ietf-poly1305)
|
||||
- none (or plain)
|
||||
|
||||
The Shadowsocks 2022 new protocol format improves performance and includes complete replay protection, resolving the following security issues of the old protocol:
|
||||
|
||||
@@ -23,10 +22,6 @@ The Shadowsocks 2022 new protocol format improves performance and includes compl
|
||||
- No UDP replay protection
|
||||
- TCP behavior that can be used for active probing
|
||||
|
||||
::: danger
|
||||
Under the "none" encryption method, traffic will be transmitted in plain text. To ensure security, do not use it on public networks.
|
||||
:::
|
||||
|
||||
## InboundConfigurationObject
|
||||
|
||||
`InboundConfigurationObject` corresponds to the `settings` item in [`InboundObject`](../inbound.md).
|
||||
|
||||
@@ -2,10 +2,6 @@
|
||||
|
||||
[Trojan](https://trojan-gfw.github.io/trojan/protocol) protocol.
|
||||
|
||||
::: danger
|
||||
Trojan is designed to work over correctly configured encrypted TLS tunnels.
|
||||
:::
|
||||
|
||||
## InboundConfigurationObject
|
||||
|
||||
`InboundConfigurationObject` corresponds to the `settings` item in [`InboundObject`](../inbound.md).
|
||||
@@ -36,6 +32,10 @@ Trojan is designed to work over correctly configured encrypted TLS tunnels.
|
||||
}
|
||||
```
|
||||
|
||||
::: warning
|
||||
Trojan must be used with transport-security [TLS](https://xtls.github.io/config/transports/tls.html); using `streamSettings.security: "none"` is only allowed when the peer is a private address (such as a private IP address or private domain name) and the link itself is trusted. In public environments, Mux is also required; otherwise, once the inner payload is itself TLS, it becomes TiT and can be easily detected ([PoC](https://github.com/XTLS/Trojan-killer)).
|
||||
:::
|
||||
|
||||
> `users`: \[ [UserObject](#userobject) \]
|
||||
|
||||
An array representing a group of users accepted by the server.
|
||||
|
||||
@@ -37,6 +37,10 @@ Unlike [VMess](./vmess.md), VLESS does not depend on system time. The authentica
|
||||
}
|
||||
```
|
||||
|
||||
::: warning
|
||||
VLESS must be used with an outer transport-security layer unless the peer is a private address (such as a private IP address or private domain name) and the link itself is trusted, or `VLESS Encryption` is enabled. In those cases, `streamSettings.security: "none"` is allowed.
|
||||
:::
|
||||
|
||||
> `users`: \[ [UserObject](#userobject) \]
|
||||
|
||||
An array representing a group of users approved by the server.
|
||||
|
||||
@@ -14,7 +14,6 @@ Current compatibility is as follows:
|
||||
- aes-128-gcm
|
||||
- chacha20-poly1305 (or chacha20-ietf-poly1305)
|
||||
- xchacha20-poly1305 (or xchacha20-ietf-poly1305)
|
||||
- none (or plain)
|
||||
|
||||
The Shadowsocks 2022 new protocol format improves performance and includes complete replay protection, resolving the following security issues of the old protocol:
|
||||
|
||||
@@ -23,10 +22,6 @@ The Shadowsocks 2022 new protocol format improves performance and includes compl
|
||||
- No UDP replay protection
|
||||
- TCP behavior that can be used for active probing
|
||||
|
||||
::: danger
|
||||
Under the "none" encryption method, traffic will be transmitted in plain text. To ensure security, do not use it on public networks.
|
||||
:::
|
||||
|
||||
## OutboundConfigurationObject
|
||||
|
||||
`OutboundConfigurationObject` corresponds to the `settings` item in [`OutboundObject`](../outbound.md).
|
||||
|
||||
@@ -2,10 +2,6 @@
|
||||
|
||||
[Trojan](https://trojan-gfw.github.io/trojan/protocol) protocol.
|
||||
|
||||
::: danger
|
||||
Trojan is designed to work over a correctly configured encrypted TLS tunnel.
|
||||
:::
|
||||
|
||||
## OutboundConfigurationObject
|
||||
|
||||
`OutboundConfigurationObject` corresponds to the `settings` item in [`OutboundObject`](../outbound.md).
|
||||
@@ -29,6 +25,10 @@ Trojan is designed to work over a correctly configured encrypted TLS tunnel.
|
||||
}
|
||||
```
|
||||
|
||||
::: warning
|
||||
Trojan must be used with transport-security [TLS](https://xtls.github.io/config/transports/tls.html); using `streamSettings.security: "none"` is only allowed when the peer is a private address (such as a private IP address or private domain name) and the link itself is trusted. In public environments, Mux is also required; otherwise, once the inner payload is itself TLS, it becomes TiT and can be easily detected ([PoC](https://github.com/XTLS/Trojan-killer)).
|
||||
:::
|
||||
|
||||
> `address`: address
|
||||
|
||||
Server address. Supports IPv4, IPv6, and domain names. Required.
|
||||
|
||||
@@ -29,6 +29,10 @@ Unlike [VMess](./vmess.md), VLESS does not depend on system time. The authentica
|
||||
}
|
||||
```
|
||||
|
||||
::: warning
|
||||
VLESS must be used with an outer transport-security layer unless the peer is a private address (such as a private IP address or private domain name) and the link itself is trusted, or `VLESS Encryption` is enabled. In those cases, `streamSettings.security: "none"` is allowed.
|
||||
:::
|
||||
|
||||
> `address`: address
|
||||
|
||||
Server address, points to the server. Supports domain names, IPv4, and IPv6.
|
||||
|
||||
@@ -57,17 +57,13 @@ User level. The connection will use the [local policy](../policy.md#levelpolicyo
|
||||
|
||||
The value of `level` corresponds to the value of `level` in [policy](../policy.md#policyobject). If not specified, the default is 0.
|
||||
|
||||
> `security`: "aes-128-gcm" | "chacha20-poly1305" | "auto" | "none" | "zero"
|
||||
> `security`: "aes-128-gcm" | "chacha20-poly1305" | "auto"
|
||||
|
||||
Encryption method. The client will use the configured encryption method to send data, and the server will automatically identify it without configuration.
|
||||
|
||||
- `"aes-128-gcm"`: Use AES-128-GCM algorithm.
|
||||
- `"chacha20-poly1305"`: Use Chacha20-Poly1305 algorithm.
|
||||
- `"auto"`: Default value. Automatically selected (uses aes-128-gcm encryption when the running framework is AMD64, ARM64, or s390x; uses Chacha20-Poly1305 encryption in other cases).
|
||||
- `"none"`: No encryption, maintains the VMess message structure.
|
||||
- `"zero"`: No encryption, direct stream copy (similar to VLESS).
|
||||
|
||||
It is not recommended to use `"none"` or `"zero"` pseudo-encryption methods without enabling TLS encryption and enforcing certificate verification. Regardless of the encryption method used, the VMess packet header is protected by encryption and authentication.
|
||||
|
||||
Note: `"auto"` only determines the AES hardware acceleration support status of the _client_. If the _server_ does not support AES hardware acceleration, you still need to manually set it to `chacha20-poly1305`. This is very important because Chacha20-Poly1305 takes about 48% more time than AES-128-GCM on platforms supporting AES acceleration, but on platforms _without_ AES acceleration, AES-128-GCM takes over 2000% more time than Chacha20-Poly1305.
|
||||
|
||||
|
||||
@@ -48,6 +48,8 @@ For direct outbounds such as [Freedom](./outbounds/freedom.md), the peer is usua
|
||||
}
|
||||
```
|
||||
|
||||
### Transport Methods
|
||||
|
||||
> `network`: "raw" | "xhttp" | "mkcp" | "grpc" | "websocket" | "httpupgrade" | "hysteria"
|
||||
|
||||
Transport method used by the data stream. The default value is `raw`.
|
||||
@@ -80,7 +82,7 @@ HTTPUpgrade configuration for the data stream. Only valid when `network` is `htt
|
||||
|
||||
Hysteria configuration for the data stream. Only valid when `network` is `hysteria`.
|
||||
|
||||
---
|
||||
### Transport Security
|
||||
|
||||
> `security`: "none" | "reality" | "tls"
|
||||
|
||||
@@ -108,7 +110,7 @@ TLS configuration. TLS is provided by Go. In normal cases the negotiation result
|
||||
Only valid when `security` is `tls`.
|
||||
It supports use with the `RAW`, `XHTTP`, `mKCP`, `gRPC`, `WebSocket`, `HTTPUpgrade`, and `Hysteria` transport methods.
|
||||
|
||||
---
|
||||
### Additional Configuration
|
||||
|
||||
> `finalmask`: [FinalMaskObject](./transports/finalmask.md)
|
||||
|
||||
@@ -117,3 +119,58 @@ FinalMask configuration, used for the final stage of traffic obfuscation.
|
||||
> `sockopt`: [SockoptObject](./transports/sockopt.md)
|
||||
|
||||
Configuration related to low-level network behavior.
|
||||
|
||||
## Transport Compatibility Quick Reference
|
||||
|
||||
Both inbounds and outbounds can configure transport methods and transport security through `streamSettings`. In actual configurations, the proxy protocol, transport method, and transport security must be compatible with one another.
|
||||
|
||||
### Inbound/Outbound Protocols and Transport Methods
|
||||
|
||||
This table corresponds to `protocol + streamSettings.network`.
|
||||
|
||||
| | `raw` | `xhttp` | `grpc` | `websocket` | `httpupgrade` | `mkcp` | `hysteria` |
|
||||
| --------------------------------------------------------------------- | --------- | --------- | --------- | ----------- | ------------- | --------- | ---------- |
|
||||
| `http` | Supported | Supported | Supported | Supported | Supported | Supported | Supported |
|
||||
| `socks` <sup><a href="#protocol-transport-note-1">[1]</a></sup> | Limited | Limited | Limited | Limited | Limited | Limited | Limited |
|
||||
| `shadowsocks` <sup><a href="#protocol-transport-note-1">[1]</a></sup> | Limited | Limited | Limited | Limited | Limited | Limited | Limited |
|
||||
| `vmess` | Supported | Supported | Supported | Supported | Supported | Supported | Supported |
|
||||
| `vless` | Supported | Supported | Supported | Supported | Supported | Supported | Supported |
|
||||
| `trojan` | Supported | Supported | Supported | Supported | Supported | Supported | Supported |
|
||||
| `hysteria` | N/A | N/A | N/A | N/A | N/A | N/A | Supported |
|
||||
| `wireguard` | N/A | N/A | N/A | N/A | N/A | N/A | N/A |
|
||||
|
||||
<small id="protocol-transport-note-1">[1] When XUDP is not enabled for Socks or Shadowsocks, UDP traffic uses the protocol's native UDP path and bypasses the configured transport method; TCP traffic is not subject to this limitation. See [XUDP](./outbound.md#muxobject).</small><br>
|
||||
|
||||
### Transport Methods and Transport Security
|
||||
|
||||
This table corresponds to `streamSettings.network + streamSettings.security`.
|
||||
|
||||
| | `none` | `tls` | `reality` |
|
||||
| ------------- | ------------- | --------- | ------------- |
|
||||
| `raw` | Supported | Supported | Supported |
|
||||
| `xhttp` | Supported | Supported | Supported |
|
||||
| `grpc` | Supported | Supported | Supported |
|
||||
| `websocket` | Supported | Supported | Not supported |
|
||||
| `httpupgrade` | Supported | Supported | Not supported |
|
||||
| `mkcp` | Supported | Supported | Not supported |
|
||||
| `hysteria` | Not supported | Required | Not supported |
|
||||
|
||||
### Inbound/Outbound Protocols and Transport Security
|
||||
|
||||
This table corresponds to `protocol + streamSettings.security`.
|
||||
|
||||
| | `none` | `tls` | `reality` | Protocol-layer security |
|
||||
| ------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------ |
|
||||
| `http` | Supported | Supported | Supported | None |
|
||||
| `socks` | Supported | Limited <sup><a href="#protocol-security-note-1">[1]</a></sup> | Limited <sup><a href="#protocol-security-note-1">[1]</a></sup> | None |
|
||||
| `shadowsocks` | Supported | Limited <sup><a href="#protocol-security-note-1">[1]</a></sup> | Limited <sup><a href="#protocol-security-note-1">[1]</a></sup> | Payload encryption and integrity <sup><a href="#protocol-security-note-2">[2]</a></sup> |
|
||||
| `vmess` | Supported | Supported | Supported | Handshake authentication and payload encryption <sup><a href="#protocol-security-note-2">[2]</a></sup> |
|
||||
| `vless` | Limited <sup><a href="#protocol-security-note-3">[3]</a></sup> | Supported | Supported | Optional Encryption <sup><a href="#protocol-security-note-4">[4]</a></sup> |
|
||||
| `trojan` | Limited <sup><a href="#protocol-security-note-3">[3]</a></sup> | Supported | Supported | Authentication only |
|
||||
| `hysteria` | Not supported | Required | Not supported | None (relies on TLS) |
|
||||
| `wireguard` | N/A | N/A | N/A | Encrypted tunnel <sup><a href="#protocol-security-note-2">[2]</a></sup> |
|
||||
|
||||
<small id="protocol-security-note-1">[1] When XUDP is not enabled for Socks or Shadowsocks, UDP traffic uses the protocol's native UDP path and bypasses the configured TLS or REALITY; TCP traffic is not subject to this limitation. See [XUDP](./outbound.md#muxobject).</small><br>
|
||||
<small id="protocol-security-note-2">[2] Shadowsocks and VMess protect the payload, but lack TLS 1.3-style forward secrecy, and their traffic patterns can still be classified. WireGuard uses sufficiently strong cryptography, but its fixed UDP signature is easy to identify and block. None of the three provides the ordinary HTTPS appearance offered by TLS/REALITY, so they are unsuitable for direct censorship circumvention.</small><br>
|
||||
<small id="protocol-security-note-3">[3] When `streamSettings.security` is `none`, VLESS (without Encryption enabled) and Trojan can connect only to private network addresses.</small><br>
|
||||
<small id="protocol-security-note-4">[4] VLESS Encryption is optional and disabled by default (`encryption: "none"`). When enabled, it allows connections to public network addresses even if `streamSettings.security` is `none`. It protects the VLESS payload but does not provide the ordinary HTTPS appearance of TLS/REALITY, so it is unsuitable for direct censorship circumvention.</small>
|
||||
|
||||
Reference in New Issue
Block a user