2 tofuproxy -- HTTP proxy with TLS certificates management
3 Copyright (C) 2021 Sergey Matveev <stargrave@stargrave.org>
5 This program is free software: you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation, version 3 of the License.
9 This program is distributed in the hope that it will be useful,
10 but WITHOUT ANY WARRANTY; without even the implied warranty of
11 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 GNU General Public License for more details.
14 You should have received a copy of the GNU General Public License
15 along with this program. If not, see <http://www.gnu.org/licenses/>.
26 "go.cypherpunks.ru/ucspi"
27 "go.stargrave.org/tofuproxy"
28 "go.stargrave.org/tofuproxy/fifos"
32 crtPath := flag.String("cert", "cert.pem", "Path to server X.509 certificate")
33 prvPath := flag.String("key", "prv.pem", "Path to server PKCS#8 private key")
34 bind := flag.String("bind", "[::1]:8080", "Bind address")
35 certs := flag.String("certs", "./certs", "Directory with pinned certificates")
36 dnsSrv := flag.String("dns", "[::1]:53", "DNS server")
37 fifosDir := flag.String("fifos", "fifos", "Directory with FIFOs")
38 notai := flag.Bool("notai", false, "Do not prepend TAI64N to logs")
40 log.SetFlags(log.Lshortfile)
43 _, caCert, err := ucspi.CertificateFromFile(*crtPath)
47 caPrv, err := ucspi.PrivateKeyFromFile(*prvPath)
53 fifos.FIFOs = *fifosDir
55 tofuproxy.Certs = *certs
56 tofuproxy.DNSSrv = *dnsSrv
57 tofuproxy.CACert = caCert
58 tofuproxy.CAPrv = caPrv
60 ln, err := net.Listen("tcp", *bind)
65 Handler: &tofuproxy.Handler{},
66 TLSNextProto: tofuproxy.TLSNextProtoS,
68 log.Println("listening:", *bind, "certs:", *certs)
69 if err := srv.Serve(ln); err != nil {