Re: [TLS] More issues with current ESNIKEYS DNS approach

2019-03-30 Thread Stephen Farrell
Hiya, On 29/03/2019 21:44, Erik Nygren wrote: > Following the discussion this week I realized some other major issues we'll > need to make sure we cover: > > 1) Handling proxies here is going to be tricky. The CONNECTi generally > needs to specify the hostname which needs to go to the server wh

[TLS] More issues with current ESNIKEYS DNS approach

2019-03-29 Thread Erik Nygren
Following the discussion this week I realized some other major issues we'll need to make sure we cover: 1) Handling proxies here is going to be tricky. The CONNECT generally needs to specify the hostname which needs to go to the server which has the ESNI key for what gets sent in the TLS handshak