Skip to content

shadowtls-server填写1.1.1.1后,客户端可以随意更换握手网站(TLS1.3域名) #122

Open
@LutongZhu

Description

@LutongZhu

之前是看到VLESS-TCP-XTLS-Vision-REALITY示例配置中需要填写支持 TLS1.3 和 h2 的网站,也可以使用 1.1.1.1:443 作为目标。
今天测试shadowtls-server也是可以配置1.1.1.1,且客户端可以随意更换握手网站(TLS1.3域名)后可以正常使用,不知道是否有不可预知问题?

sing-box服务端配置文件

{
      "type": "shadowtls",
      "listen": "::",
      "listen_port": prot,
      "detour": "shadowsocks-in",
      "version": 3,
      "users": [
        {
          "password": "password"
        }
      ],
      "handshake": {
        "server": "1.1.1.1",
        "server_port": 443
      },
      "strict_mode": true
    },
    {
      "type": "shadowsocks",
      "tag": "shadowsocks-in",
      "listen": "127.0.0.1",
      "listen_port": prot,
      "method": "2022-blake3-aes-128-gcm",
      "password": "password==",
      "multiplex": {
        "enabled": true
      }
    }

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions