Documentation
¶
Overview ¶
Package tlsfront implements advanced TLS fronting with real certificate fetching. This makes the proxy indistinguishable from a real HTTPS server.
Package tlsfront implements TLS fronting with real server responses.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type CachedCert ¶
type CachedCert struct {
Chain []*x509.Certificate
RawChain [][]byte // Raw DER-encoded certificates
FetchedAt time.Time
ExpiresAt time.Time
Host string
}
CachedCert holds a fetched certificate with metadata.
func (*CachedCert) GetRawCertChain ¶
func (c *CachedCert) GetRawCertChain() [][]byte
GetRawCertChain returns the raw DER-encoded certificate chain.
func (*CachedCert) IsExpired ¶
func (c *CachedCert) IsExpired() bool
IsExpired checks if the cached cert should be refreshed.
type CertFetcher ¶
type CertFetcher struct {
// contains filtered or unexported fields
}
CertFetcher fetches and caches real TLS certificates from mask hosts.
func NewCertFetcher ¶
func NewCertFetcher(refreshHours int, sni string) *CertFetcher
NewCertFetcher creates a new certificate fetcher. sni is the ServerName to send in TLS handshake (the domain to mimic).
func (*CertFetcher) CachedCert ¶ added in v0.6.8
func (f *CertFetcher) CachedCert(host string, port int) *CachedCert
CachedCert returns the last fetched certificate, even when it is due for refresh. It never performs network I/O. Callers must treat it as immutable. A nil result means no successful fetch has completed for this endpoint.
func (*CertFetcher) FetchCert ¶
func (f *CertFetcher) FetchCert(host string, port int) (*CachedCert, error)
FetchCert fetches a real certificate from the mask host. Uses cache if available and not expired.
func (*CertFetcher) StartBackgroundRefresh ¶
func (f *CertFetcher) StartBackgroundRefresh(host string, port int)
StartBackgroundRefresh starts a goroutine to refresh certificates before expiry.
type ServerHelloFetcher ¶ added in v0.3.1
type ServerHelloFetcher struct {
// contains filtered or unexported fields
}
ServerHelloFetcher fetches and caches real ServerHello responses from mask hosts.
func NewServerHelloFetcher ¶ added in v0.3.1
func NewServerHelloFetcher(host string, port int) *ServerHelloFetcher
NewServerHelloFetcher creates a fetcher for the given mask host.
func (*ServerHelloFetcher) CertRecordLen ¶ added in v0.4.1
func (f *ServerHelloFetcher) CertRecordLen() int
CertRecordLen returns the payload length of the mask backend's first ApplicationData (encrypted certificate) record from the last successful fetch, or 0 if not yet captured. Used to size our fake cert record to match.
func (*ServerHelloFetcher) GetServerHelloTemplate ¶ added in v0.3.1
func (f *ServerHelloFetcher) GetServerHelloTemplate() (response []byte, randomOffset int, err error)
GetServerHelloTemplate returns a cached ServerHello response template. The caller must patch the random field at the returned offset. It never performs network I/O, and retains the last good template on refresh failure.
func (*ServerHelloFetcher) Refresh ¶ added in v0.6.8
func (f *ServerHelloFetcher) Refresh() error
Refresh fetches an expired or missing template. Call it only during startup or in a background worker, never from a connection event loop.
func (*ServerHelloFetcher) StartBackgroundRefresh ¶ added in v0.3.1
func (f *ServerHelloFetcher) StartBackgroundRefresh()
StartBackgroundRefresh starts periodic refresh of the cached ServerHello.