Documentation
¶
Overview ¶
Package tlsfront implements advanced TLS fronting with real certificate fetching. This makes the proxy indistinguishable from a real HTTPS server.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type CachedCert ¶
type CachedCert struct {
Chain []*x509.Certificate
RawChain [][]byte // Raw DER-encoded certificates
FetchedAt time.Time
ExpiresAt time.Time
Host string
}
CachedCert holds a fetched certificate with metadata.
func (*CachedCert) GetRawCertChain ¶
func (c *CachedCert) GetRawCertChain() [][]byte
GetRawCertChain returns the raw DER-encoded certificate chain.
func (*CachedCert) IsExpired ¶
func (c *CachedCert) IsExpired() bool
IsExpired checks if the cached cert should be refreshed.
type CertFetcher ¶
type CertFetcher struct {
// contains filtered or unexported fields
}
CertFetcher fetches and caches real TLS certificates from mask hosts.
func NewCertFetcher ¶
func NewCertFetcher(refreshHours int) *CertFetcher
NewCertFetcher creates a new certificate fetcher.
func (*CertFetcher) FetchCert ¶
func (f *CertFetcher) FetchCert(host string, port int) (*CachedCert, error)
FetchCert fetches a real certificate from the mask host. Uses cache if available and not expired.
func (*CertFetcher) StartBackgroundRefresh ¶
func (f *CertFetcher) StartBackgroundRefresh(host string, port int)
StartBackgroundRefresh starts a goroutine to refresh certificates before expiry.
Click to show internal directories.
Click to hide internal directories.