File
Blob: spec/cipher/config.go
| 1 | package cipher |
| 2 | |
| 3 | import ( |
| 4 | "crypto/tls" |
| 5 | "crypto/x509" |
| 6 | |
| 7 | "github.com/quic-go/quic-go/http3" |
| 8 | ) |
| 9 | |
| 10 | var ( |
| 11 | H3Protos = []string{http3.NextProtoH3} |
| 12 | ) |
| 13 | |
| 14 | // we will require the use of ECDSA certificates for Chord |
| 15 | func GetPeerTLSConfig(ca *x509.CertPool, node tls.Certificate, protos []string) *tls.Config { |
| 16 | return &tls.Config{ |
| 17 | RootCAs: ca, |
| 18 | ClientCAs: ca, |
| 19 | Certificates: []tls.Certificate{node}, |
| 20 | ClientAuth: tls.RequireAndVerifyClientCert, |
| 21 | NextProtos: protos, |
| 22 | MinVersion: tls.VersionTLS13, |
| 23 | CipherSuites: []uint16{ |
| 24 | // TLS 1.3 ciphers |
| 25 | tls.TLS_AES_128_GCM_SHA256, |
| 26 | tls.TLS_AES_256_GCM_SHA384, |
| 27 | tls.TLS_CHACHA20_POLY1305_SHA256, |
| 28 | }, |
| 29 | CurvePreferences: []tls.CurveID{ |
| 30 | tls.X25519, tls.CurveP256, |
| 31 | }, |
| 32 | } |
| 33 | } |
| 34 | |
| 35 | func GetClientTLSConfig(caClient *x509.CertPool, provider CertProviderFunc, protos []string) *tls.Config { |
| 36 | cfg := GetGatewayTLSConfig(provider, protos) |
| 37 | cfg.ClientCAs = caClient |
| 38 | cfg.ClientAuth = tls.RequireAndVerifyClientCert |
| 39 | cfg.MinVersion = tls.VersionTLS13 |
| 40 | return cfg |
| 41 | } |
| 42 | |
| 43 | // our acme cert generation uses ECDSA (P-256), thus we will skip |
| 44 | // ciphers that do not do elliptic curve DH |
| 45 | func GetGatewayTLSConfig(provider CertProviderFunc, protos []string) *tls.Config { |
| 46 | return &tls.Config{ |
| 47 | GetCertificate: provider, |
| 48 | ClientAuth: tls.NoClientCert, |
| 49 | NextProtos: protos, |
| 50 | MinVersion: tls.VersionTLS12, |
| 51 | // https://wiki.mozilla.org/Security/Server_Side_TLS (Intermediate compatibility) |
| 52 | CipherSuites: []uint16{ |
| 53 | // TLS 1.3 ciphers |
| 54 | tls.TLS_AES_128_GCM_SHA256, |
| 55 | tls.TLS_AES_256_GCM_SHA384, |
| 56 | tls.TLS_CHACHA20_POLY1305_SHA256, |
| 57 | // TLS 1.2 ciphers |
| 58 | tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, |
| 59 | tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, |
| 60 | tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305, |
| 61 | }, |
| 62 | CurvePreferences: []tls.CurveID{ |
| 63 | tls.X25519, tls.CurveP256, tls.CurveP384, |
| 64 | }, |
| 65 | } |
| 66 | } |