ProxymanApp / ProxymanApp/Proxyman

Improve How we fetch the remote Certificate

Open
#539 1 comment 0 reactions 1 assignee View on GitHub

@NghiaTranUIT is already working on this.

Since Jul 1, 2020.

✅ Done enhancement
Dominant language
No language data
Stars
7k
Forks
237
PR merge metrics
No merged PRs in 30d

Description

Description

Currently, we're using OpenSSL to fetch the remote certificate, but it doesn't work well in the following scenario:

  • Support External Proxy (HTTP/HTTPS and Socks5)
  • Custom Client Certificate
  • Get some errors if the domain is on an internal network
  • Some crashes on OpenSSL
  • Hard to extend the feature since it's low-level code

It's time to refactor it and find a better alternative.

Acceptance Criteria
  • Use NIOSSLClientHandler and NIOSSLCustomVerificationCallback to get the Remote Certificate during Certificate Evaluation
  • Remove all OpenSSL and relevant code
  • Test some edge cases and make sure it works

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.