Omit SNI in uTLS connections when it would contain an IP address.

Important for us as we are likely to connect to servers like 1.1.1.1 and
8.8.8.8.
This commit is contained in:
David Fifield
2022-01-02 19:16:00 -07:00
parent fec00a2a78
commit 74a0ff06f4
+9
View File
@@ -71,6 +71,15 @@ func utlsDialContext(ctx context.Context, network, addr string, config *utls.Con
return nil, err
}
uconn := utls.UClient(conn, config, *id)
// Manually remove the SNI if it contains an IP address.
// https://github.com/refraction-networking/utls/issues/96
if net.ParseIP(config.ServerName) != nil {
err := uconn.RemoveSNIExtension()
if err != nil {
uconn.Close()
return nil, err
}
}
// We must call Handshake before returning, or else the UConn may not
// actually use the selected ClientHelloID. It depends on whether a Read
// or a Write happens first. If a Read happens first, the connection