<feed xmlns='http://www.w3.org/2005/Atom'>
<title>mitmux/internal/ca/ca.go, branch main</title>
<subtitle>Terminal-based intercepting HTTP proxy.
</subtitle>
<id>https://srdusr.com/git/mitmux/atom?h=main</id>
<link rel='self' href='https://srdusr.com/git/mitmux/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/mitmux/'/>
<updated>2024-01-27T19:47:00+00:00</updated>
<entry>
<title>TLS interception: per-host leaf certs, terminate-and-resign MITM, native HTTP/2</title>
<updated>2024-01-27T19:47:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2024-01-27T19:47:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/mitmux/commit/?id=f2f0a2135a202e3e15d2a8cbfbd791aad9b04f3a'/>
<id>urn:sha1:f2f0a2135a202e3e15d2a8cbfbd791aad9b04f3a</id>
<content type='text'>
Implements build-order step 2. CA gains LeafFor(host), signing and
caching per-host leaf certificates on demand. The proxy's CONNECT
handler now terminates TLS with the client using a matching leaf cert
instead of tunneling raw bytes, and forwards each request upstream
over its own independently negotiated TLS connection.

Client-side and upstream-side ALPN are negotiated separately rather
than one being forced to mirror the other: an http.Transport configured
via http2.ConfigureTransport auto-bridges HTTP/1.1 and HTTP/2 on each
side independently, so e.g. an HTTP/1.1-only client reaching an
HTTP/2-preferring origin still works instead of failing the handshake
(caught by testing curl --http1.1 against example.com before this fix).

Verified live: plain HTTP passthrough, HTTPS with default (H2) and
forced HTTP/1.1 clients, and that requests without the mitmux CA
trusted are correctly rejected.
</content>
</entry>
<entry>
<title>Scaffold mitmux: proxy daemon, CA generation, HTTP/CONNECT passthrough</title>
<updated>2024-01-16T14:26:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2024-01-16T14:26:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/mitmux/commit/?id=1125afc47b9d6e68d95d0ffdbb74514f4618e624'/>
<id>urn:sha1:1125afc47b9d6e68d95d0ffdbb74514f4618e624</id>
<content type='text'>
Implements build-order step 1: headless proxy daemon (mitmuxd) with
plaintext HTTP passthrough and raw CONNECT tunneling, plus root CA
generation/persistence for later TLS interception. Verified live
against real HTTP and HTTPS requests through the proxy.
</content>
</entry>
</feed>
