Skip to content

Support for TLS ECH (Encrypted Client Hello) #44165

Description

@wiktor-k

Title: Add support for accepting encrypted Client Hellos

Description:
SNI information in the initial TLS handshake is not encrypted by default, ECH solves this issue.

Browsers support RFC 9849 - TLS Encrypted Client Hello already for some time: Firefox since version 118, Chrome since 117.

Some servers also support ECH, e.g. Nginx and haproxy.

[optional Relevant Links:]

Any extra documentation required to understand the issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/tlsenhancementFeature requests. Not bugs or questions.no stalebotDisables stalebot from closing an issue

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions