diff options
| author | srdusr <[email protected]> | 2024-01-27 21:47:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2024-01-27 21:47:00 +0200 |
| commit | f2f0a2135a202e3e15d2a8cbfbd791aad9b04f3a (patch) | |
| tree | 3850e9de9355e8ab3b99b68fb69e1ef6df50e0cf /cmd | |
| parent | 1125afc47b9d6e68d95d0ffdbb74514f4618e624 (diff) | |
| download | mitmux-f2f0a2135a202e3e15d2a8cbfbd791aad9b04f3a.tar.gz mitmux-f2f0a2135a202e3e15d2a8cbfbd791aad9b04f3a.zip | |
TLS interception: per-host leaf certs, terminate-and-resign MITM, native HTTP/2
Implements build-order step 2. CA gains LeafFor(host), signing and
caching per-host leaf certificates on demand. The proxy's CONNECT
handler now terminates TLS with the client using a matching leaf cert
instead of tunneling raw bytes, and forwards each request upstream
over its own independently negotiated TLS connection.
Client-side and upstream-side ALPN are negotiated separately rather
than one being forced to mirror the other: an http.Transport configured
via http2.ConfigureTransport auto-bridges HTTP/1.1 and HTTP/2 on each
side independently, so e.g. an HTTP/1.1-only client reaching an
HTTP/2-preferring origin still works instead of failing the handshake
(caught by testing curl --http1.1 against example.com before this fix).
Verified live: plain HTTP passthrough, HTTPS with default (H2) and
forced HTTP/1.1 clients, and that requests without the mitmux CA
trusted are correctly rejected.
Diffstat (limited to 'cmd')
| -rw-r--r-- | cmd/mitmuxd/main.go | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/cmd/mitmuxd/main.go b/cmd/mitmuxd/main.go index 400ca82..f79f2cf 100644 --- a/cmd/mitmuxd/main.go +++ b/cmd/mitmuxd/main.go @@ -34,9 +34,9 @@ func main() { if err != nil { log.Fatalf("load CA: %v", err) } - log.Printf("CA ready: %s", root.Cert.Subject.CommonName) + log.Printf("CA ready: %s (install %s/ca.pem in your client's trust store to avoid TLS warnings)", root.Cert.Subject.CommonName, dir) - srv := proxy.New(*listen) + srv := proxy.New(*listen, root) errCh := make(chan error, 1) go func() { |