srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/internal/proxy/repeat.go
diff options
context:
space:
mode:
Diffstat (limited to 'internal/proxy/repeat.go')
-rw-r--r--internal/proxy/repeat.go15
1 files changed, 11 insertions, 4 deletions
diff --git a/internal/proxy/repeat.go b/internal/proxy/repeat.go
index f682b99..8e7836d 100644
--- a/internal/proxy/repeat.go
+++ b/internal/proxy/repeat.go
@@ -36,7 +36,7 @@ func (s *Server) sendRaw(ctx context.Context, scheme, host string, raw []byte, s
started := time.Now()
method, path := parseRequestLine(raw)
- conn, err := dialForRepeat(ctx, scheme, host)
+ conn, err := s.dialForRepeat(ctx, scheme, host)
if err != nil {
return s.recordRaw(started, time.Since(started), scheme, host, method, path, raw, nil, false, false, 0, err.Error(), source)
}
@@ -101,8 +101,11 @@ func (s *Server) recordRaw(started time.Time, duration time.Duration, scheme, ho
}
// dialForRepeat connects to host for scheme, forcing HTTP/1.1 over ALPN
-// when TLS is involved (see Repeat's doc comment for why).
-func dialForRepeat(ctx context.Context, scheme, host string) (net.Conn, error) {
+// when TLS is involved (see Repeat's doc comment for why), presenting a
+// client certificate if one is configured for hostname (see
+// clientCertFor) - a resent or fuzzed request against a mutual-TLS host
+// needs one just as much as a live proxied request does.
+func (s *Server) dialForRepeat(ctx context.Context, scheme, host string) (net.Conn, error) {
nd := &net.Dialer{Timeout: 10 * time.Second}
if scheme != "https" {
hostPort := host
@@ -122,7 +125,11 @@ func dialForRepeat(ctx context.Context, scheme, host string) (net.Conn, error) {
if err != nil {
return nil, err
}
- conn := tls.Client(raw, &tls.Config{ServerName: hostname, NextProtos: []string{"http/1.1"}})
+ cfg := &tls.Config{ServerName: hostname, NextProtos: []string{"http/1.1"}}
+ if cert := s.clientCertFor(hostname); cert != nil {
+ cfg.Certificates = []tls.Certificate{*cert}
+ }
+ conn := tls.Client(raw, cfg)
if err := conn.HandshakeContext(ctx); err != nil {
raw.Close()
return nil, err