mirror of
https://github.com/XTLS/Xray-docs-next.git
synced 2026-10-10 08:18:10 +03:00
TLS: tls leafCertHash → tls hash
This commit is contained in:
@@ -236,7 +236,7 @@ Parameters passed include:
|
||||
|
||||
Used to specify the SHA256 hash of the remote server's certificate. It uses hex encoding and is case-insensitive. For example: `e8e2d387fdbffeb38e9c9065cf30a97ee23c0e3d32ee6f78ffae40966befccc9`. You can specify multiple hash values separated by `,`; verification passes if any of them match.
|
||||
|
||||
This encoding matches the SHA-256 Certificate Fingerprint found in the Chrome certificate viewer and the format used on crt.sh. You can calculate it using `xray tls leafCertHash --cert <cert.pem>` or `openssl x509 -noout -fingerprint -sha256 -in cert.pem` (the format with colons generated by OpenSSL is supported). Additionally, `xray tls ping` will output the remote certificate's SHA256 hash.
|
||||
This encoding matches the SHA-256 Certificate Fingerprint found in the Chrome certificate viewer and the format used on crt.sh. You can calculate it using `xray tls hash --cert <cert.pem>` or `openssl x509 -noout -fingerprint -sha256 -in cert.pem` (the format with colons generated by OpenSSL is supported). Additionally, `xray tls ping` will output the remote certificate's SHA256 hash.
|
||||
|
||||
This mechanism overrides the default certificate validation and operates in two scenarios:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user