An L4 reverse proxy with protocol multiplexer, written in Rust
-
Updated
Jul 29, 2026 - Rust
An L4 reverse proxy with protocol multiplexer, written in Rust
为CDN全面开启ECH的DoH服务,基于Cloudflare Workers,适用于Cloudflare CDN / Meta CDN
Encrypted Client Hello with Split Mode Topology; +ECH Resolver, Dialer, RoundTripper, Publisher
Encrypted Client Hello (ECH) config parser and generator.
Multi-listener SNI/Host-routing TLS gateway: dynamic per-SNI certificate issuance on termination, with ECH / TLS / HTTP / raw upstreams.
Discreet end-to-end encrypted file handoff with Cloudflare or self-hosted backends
Network threat detection lab — Encrypted Client Hello, post-quantum TLS, JA4 fingerprinting, DNS tunneling, C2 beaconing, AI/MCP egress. Sigma rules, SOC playbooks, and CI-validated detection-as-code.
Suricata IDS lab — 23 custom detection rules with MITRE ATT&CK metadata, JA4 fingerprinting, Encrypted Client Hello and post-quantum TLS detection, false-positive tuning, and engine-validated detection-as-code CI.
Browser-based ECH demo — draft-ietf-tls-esni. TLS 1.3 protects every byte except the hostname it announces first. Real HPKE seals the ClientHelloInner; a network observer sees only the outer. Tamper the ECHConfig and watch the real open fail. Metadata is the leak encryption doesn't close. No backends. No simulated math.
BoringSSL-linked nginx build tooling with HTTP/3, Encrypted Client Hello and post-quantum key exchange, optimised for AMD Zen 2 - plus annotated TLS hardening and L7 anti-DDoS examples
ECH (Encrypted Client Hello) compliance scanner — test RFC 9849 deployment
Server-side ECH for QUIC — in 2 lines.
Add a description, image, and links to the encrypted-client-hello topic page so that developers can more easily learn about it.
To associate your repository with the encrypted-client-hello topic, visit your repo's landing page and select "manage topics."