Skip to content
File

Blob: spec/cipher/config.go

go67 lines
1package cipher
2 
3import (
4 "crypto/tls"
5 "crypto/x509"
6 
7 "github.com/quic-go/quic-go/http3"
8)
9 
10var (
11 H3Protos = []string{http3.NextProtoH3}
12)
13 
14// we will require the use of ECDSA certificates for Chord
15func GetPeerTLSConfig(ca *x509.CertPool, node tls.Certificate, protos []string) *tls.Config {
16 return &tls.Config{
17 RootCAs: ca,
18 ClientCAs: ca,
19 Certificates: []tls.Certificate{node},
20 ClientAuth: tls.RequireAndVerifyClientCert,
21 NextProtos: protos,
22 MinVersion: tls.VersionTLS13,
23 CipherSuites: []uint16{
24 // TLS 1.3 ciphers
25 tls.TLS_AES_128_GCM_SHA256,
26 tls.TLS_AES_256_GCM_SHA384,
27 tls.TLS_CHACHA20_POLY1305_SHA256,
28 },
29 CurvePreferences: []tls.CurveID{
30 tls.X25519, tls.CurveP256,
31 },
32 }
33}
34 
35func GetClientTLSConfig(caClient *x509.CertPool, provider CertProviderFunc, protos []string) *tls.Config {
36 cfg := GetGatewayTLSConfig(provider, protos)
37 cfg.ClientCAs = caClient
38 cfg.ClientAuth = tls.RequireAndVerifyClientCert
39 cfg.MinVersion = tls.VersionTLS13
40 return cfg
41}
42 
43// our acme cert generation uses ECDSA (P-256), thus we will skip
44// ciphers that do not do elliptic curve DH
45func GetGatewayTLSConfig(provider CertProviderFunc, protos []string) *tls.Config {
46 return &tls.Config{
47 GetCertificate: provider,
48 ClientAuth: tls.NoClientCert,
49 NextProtos: protos,
50 MinVersion: tls.VersionTLS12,
51 // https://wiki.mozilla.org/Security/Server_Side_TLS (Intermediate compatibility)
52 CipherSuites: []uint16{
53 // TLS 1.3 ciphers
54 tls.TLS_AES_128_GCM_SHA256,
55 tls.TLS_AES_256_GCM_SHA384,
56 tls.TLS_CHACHA20_POLY1305_SHA256,
57 // TLS 1.2 ciphers
58 tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
59 tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
60 tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,
61 },
62 CurvePreferences: []tls.CurveID{
63 tls.X25519, tls.CurveP256, tls.CurveP384,
64 },
65 }
66}