TLS Encrypted Client Hello (ECH) for XMPP
Hi, I'd like to check if anyone explored the idea of implementing ECH [0] for XMPP? The rationale would be to hide the last bits that are sent plaintext when connecting: hostname (SNI) and protocols (ALPN). I'm aware that this is not simple, would require close collaboration of client and server developers and there's a large potential for bikeshedding (e.g. whether to use SVBC records [1] or Host Meta 2 [2]) but the only resource I found on this topic [3] ended without a clear conclusion. From the practical point of view it seems that ECH will be available soon in OpenSSL and some web servers already implement that [4] [5]. Thanks for your time! Kind regards, Wiktor [0]: https://www.rfc-editor.org/rfc/rfc9849.html [1]: https://www.rfc-editor.org/rfc/rfc9460 [2]: https://xmpp.org/extensions/xep-0487.html [3]: https://mail.jabber.org/hyperkitty/list/standards@xmpp.org/thread/6WSGNTADZ6... [4]: https://github.com/nginx/nginx/pull/840 [5]: https://github.com/haproxy/haproxy/issues/1924
Hi Wiktor! Yep I've got a local branch of xmpp-proxy with client-side support for ECH but I'm not sure it makes sense to push it without server-side support which is still blocked in my library <https://github.com/rustls/rustls/issues/1980> It might when openssl or nginx have support. Thanks, Travis
Hi Travis,
Yep I've got a local branch of xmpp-proxy with client-side support for ECH but I'm not sure it makes sense to push it without server-side support which is still blocked in my library <https://github.com/rustls/rustls/issues/1980>
Thanks for the tracking ticket, subscribed!
It might when openssl or nginx have support.
Yep, hopefully that happens sooner than later (nginx already has support and openssl 4 release should be imminent). Have a nice day! Kind regards, Wiktor
participants (2)
-
Travis Burtrum -
Wiktor Kwapisiewicz