2 tofuproxy -- HTTP proxy with TLS certificates management
3 Copyright (C) 2021 Sergey Matveev <stargrave@stargrave.org>
5 This program is free software: you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation, version 3 of the License.
9 This program is distributed in the hope that it will be useful,
10 but WITHOUT ANY WARRANTY; without even the implied warranty of
11 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 GNU General Public License for more details.
14 You should have received a copy of the GNU General Public License
15 along with this program. If not, see <http://www.gnu.org/licenses/>.
29 "github.com/miekg/dns"
34 func dane(addr string, cert *x509.Certificate) (bool, bool) {
40 cols := strings.Split(addr, ":")
46 m.SetQuestion(dns.Fqdn(fmt.Sprintf("_%s._tcp.%s", port, host)), dns.TypeTLSA)
47 msg, err := dns.Exchange(m, DNSSrv)
49 log.Printf("DNS: %+v\n", err)
52 if msg.MsgHdr.Rcode != dns.RcodeSuccess {
56 for _, answer := range msg.Answer {
57 tlsa, ok := answer.(*dns.TLSA)
67 switch tlsa.Selector {
71 toMatch = cert.RawSubjectPublicKeyInfo
74 switch tlsa.MatchingType {
78 our := sha256.Sum256(toMatch)
81 our := sha512.Sum512(toMatch)
84 if tlsa.Certificate == hex.EncodeToString(hsh) {