From f2f0a2135a202e3e15d2a8cbfbd791aad9b04f3a Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Sat, 27 Jan 2024 21:47:00 +0200 Subject: TLS interception: per-host leaf certs, terminate-and-resign MITM, native HTTP/2 Implements build-order step 2. CA gains LeafFor(host), signing and caching per-host leaf certificates on demand. The proxy's CONNECT handler now terminates TLS with the client using a matching leaf cert instead of tunneling raw bytes, and forwards each request upstream over its own independently negotiated TLS connection. Client-side and upstream-side ALPN are negotiated separately rather than one being forced to mirror the other: an http.Transport configured via http2.ConfigureTransport auto-bridges HTTP/1.1 and HTTP/2 on each side independently, so e.g. an HTTP/1.1-only client reaching an HTTP/2-preferring origin still works instead of failing the handshake (caught by testing curl --http1.1 against example.com before this fix). Verified live: plain HTTP passthrough, HTTPS with default (H2) and forced HTTP/1.1 clients, and that requests without the mitmux CA trusted are correctly rejected. --- go.mod | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'go.mod') diff --git a/go.mod b/go.mod index 030c225..5b564a3 100644 --- a/go.mod +++ b/go.mod @@ -1,3 +1,8 @@ module mitmux go 1.26.5 + +require ( + golang.org/x/net v0.58.0 // indirect + golang.org/x/text v0.41.0 // indirect +) -- cgit v1.2.3