Skip to content

feature request: encrypted SNI #2327

@Lennie

Description

@Lennie

Not sure if this is the right place, I'm probably early to request this anyway.

If I understand correctly, this needs:

  • an extra TLS extension
  • the webserver should understand 2 or more 'SNI names' for the same name, the plain text name plus a number of encrypted names.
  • generate a new key regularly
  • needs a way to tell DNS about what key clients can use

https://tools.ietf.org/html/draft-rescorla-tls-esni-00

Sounds to me like if there are multiple web servers, you'd might want to have a centralized program pushing updates to the servers and DNS.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions