diff options
| author | srdusr <[email protected]> | 2024-01-27 21:47:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2024-01-27 21:47:00 +0200 |
| commit | f2f0a2135a202e3e15d2a8cbfbd791aad9b04f3a (patch) | |
| tree | 3850e9de9355e8ab3b99b68fb69e1ef6df50e0cf /go.mod | |
| parent | 1125afc47b9d6e68d95d0ffdbb74514f4618e624 (diff) | |
| download | mitmux-f2f0a2135a202e3e15d2a8cbfbd791aad9b04f3a.tar.gz mitmux-f2f0a2135a202e3e15d2a8cbfbd791aad9b04f3a.zip | |
TLS interception: per-host leaf certs, terminate-and-resign MITM, native HTTP/2
Implements build-order step 2. CA gains LeafFor(host), signing and
caching per-host leaf certificates on demand. The proxy's CONNECT
handler now terminates TLS with the client using a matching leaf cert
instead of tunneling raw bytes, and forwards each request upstream
over its own independently negotiated TLS connection.
Client-side and upstream-side ALPN are negotiated separately rather
than one being forced to mirror the other: an http.Transport configured
via http2.ConfigureTransport auto-bridges HTTP/1.1 and HTTP/2 on each
side independently, so e.g. an HTTP/1.1-only client reaching an
HTTP/2-preferring origin still works instead of failing the handshake
(caught by testing curl --http1.1 against example.com before this fix).
Verified live: plain HTTP passthrough, HTTPS with default (H2) and
forced HTTP/1.1 clients, and that requests without the mitmux CA
trusted are correctly rejected.
Diffstat (limited to 'go.mod')
| -rw-r--r-- | go.mod | 5 |
1 files changed, 5 insertions, 0 deletions
@@ -1,3 +1,8 @@ module mitmux go 1.26.5 + +require ( + golang.org/x/net v0.58.0 // indirect + golang.org/x/text v0.41.0 // indirect +) |