Post B8nSnQBM6ntL2rOYYi by privateger@plasmatrap.com
(DIR) More posts by privateger@plasmatrap.com
(DIR) Post #B8nSnPxWwCpgLyvW0e by zaki@plasmatrap.com
0 likes, 0 repeats
i mean, there shouldn't really be much stopping one from having their outer/unencrypted sni set to something like ip.isp.tld now, no?
(DIR) Post #B8nSnQBM6ntL2rOYYi by privateger@plasmatrap.com
0 likes, 0 repeats
@zaki basically nothing, nothe client does not get to pick the outer SNI typically though. It gets an ECHConfig, where public_name tells it what outer SNI to usethe requirements are:- ip.isp.tld must a valid DNS-style hostname- the ECH frontend must be authoritative for it- the frontend should have a valid TLS certificate for ip.isp.tld, because rejection makes it fall back to that to update the ECH configCloudflare, for example, uses cloudflare-ech.com for every outer SNI, across all ECH capable sites