An L4 reverse proxy with protocol multiplexer, written in Rust
-
Updated
Jul 21, 2026 - Rust
An L4 reverse proxy with protocol multiplexer, written in Rust
为CDN全面开启ECH的DoH服务,基于Cloudflare Workers,适用于Cloudflare CDN / Meta CDN
Encrypted Client Hello with Split Mode Topology; +ECH Resolver, Dialer, RoundTripper, Publisher
Encrypted Client Hello (ECH) config parser and generator.
Multi-listener SNI/Host-routing TLS gateway: dynamic per-SNI certificate issuance on termination, with ECH / TLS / HTTP / raw upstreams.
Discreet end-to-end encrypted file handoff with Cloudflare or self-hosted backends
Browser-based ECH demo — draft-ietf-tls-esni. TLS 1.3 protects every byte except the hostname it announces first. Real HPKE seals the ClientHelloInner; a network observer sees only the outer. Tamper the ECHConfig and watch the real open fail. Metadata is the leak encryption doesn't close. No backends. No simulated math.
ECH (Encrypted Client Hello) compliance scanner — test RFC 9849 deployment
Server-side ECH for QUIC — in 2 lines.
Add a description, image, and links to the encrypted-client-hello topic page so that developers can more easily learn about it.
To associate your repository with the encrypted-client-hello topic, visit your repo's landing page and select "manage topics."