Title: Add support for accepting encrypted Client Hellos
Description:
SNI information in the initial TLS handshake is not encrypted by default, ECH solves this issue.
Browsers support RFC 9849 - TLS Encrypted Client Hello already for some time: Firefox since version 118, Chrome since 117.
Some servers also support ECH, e.g. Nginx and haproxy.
[optional Relevant Links:]
Any extra documentation required to understand the issue.
Title: Add support for accepting encrypted Client Hellos
Description:
SNI information in the initial TLS handshake is not encrypted by default, ECH solves this issue.
Browsers support RFC 9849 - TLS Encrypted Client Hello already for some time: Firefox since version 118, Chrome since 117.
Some servers also support ECH, e.g. Nginx and haproxy.
[optional Relevant Links:]