tlsfront

package
v0.6.8 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: Apache-2.0 Imports: 9 Imported by: 0

Documentation

Overview

Package tlsfront implements advanced TLS fronting with real certificate fetching. This makes the proxy indistinguishable from a real HTTPS server.

Package tlsfront implements TLS fronting with real server responses.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type CachedCert

type CachedCert struct {
	Chain     []*x509.Certificate
	RawChain  [][]byte // Raw DER-encoded certificates
	FetchedAt time.Time
	ExpiresAt time.Time
	Host      string
}

CachedCert holds a fetched certificate with metadata.

func (*CachedCert) GetRawCertChain

func (c *CachedCert) GetRawCertChain() [][]byte

GetRawCertChain returns the raw DER-encoded certificate chain.

func (*CachedCert) IsExpired

func (c *CachedCert) IsExpired() bool

IsExpired checks if the cached cert should be refreshed.

type CertFetcher

type CertFetcher struct {
	// contains filtered or unexported fields
}

CertFetcher fetches and caches real TLS certificates from mask hosts.

func NewCertFetcher

func NewCertFetcher(refreshHours int, sni string) *CertFetcher

NewCertFetcher creates a new certificate fetcher. sni is the ServerName to send in TLS handshake (the domain to mimic).

func (*CertFetcher) CachedCert added in v0.6.8

func (f *CertFetcher) CachedCert(host string, port int) *CachedCert

CachedCert returns the last fetched certificate, even when it is due for refresh. It never performs network I/O. Callers must treat it as immutable. A nil result means no successful fetch has completed for this endpoint.

func (*CertFetcher) FetchCert

func (f *CertFetcher) FetchCert(host string, port int) (*CachedCert, error)

FetchCert fetches a real certificate from the mask host. Uses cache if available and not expired.

func (*CertFetcher) StartBackgroundRefresh

func (f *CertFetcher) StartBackgroundRefresh(host string, port int)

StartBackgroundRefresh starts a goroutine to refresh certificates before expiry.

type ServerHelloFetcher added in v0.3.1

type ServerHelloFetcher struct {
	// contains filtered or unexported fields
}

ServerHelloFetcher fetches and caches real ServerHello responses from mask hosts.

func NewServerHelloFetcher added in v0.3.1

func NewServerHelloFetcher(host string, port int) *ServerHelloFetcher

NewServerHelloFetcher creates a fetcher for the given mask host.

func (*ServerHelloFetcher) CertRecordLen added in v0.4.1

func (f *ServerHelloFetcher) CertRecordLen() int

CertRecordLen returns the payload length of the mask backend's first ApplicationData (encrypted certificate) record from the last successful fetch, or 0 if not yet captured. Used to size our fake cert record to match.

func (*ServerHelloFetcher) GetServerHelloTemplate added in v0.3.1

func (f *ServerHelloFetcher) GetServerHelloTemplate() (response []byte, randomOffset int, err error)

GetServerHelloTemplate returns a cached ServerHello response template. The caller must patch the random field at the returned offset. It never performs network I/O, and retains the last good template on refresh failure.

func (*ServerHelloFetcher) Refresh added in v0.6.8

func (f *ServerHelloFetcher) Refresh() error

Refresh fetches an expired or missing template. Call it only during startup or in a background worker, never from a connection event loop.

func (*ServerHelloFetcher) StartBackgroundRefresh added in v0.3.1

func (f *ServerHelloFetcher) StartBackgroundRefresh()

StartBackgroundRefresh starts periodic refresh of the cached ServerHello.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL