1 // tofuproxy -- flexible HTTP/HTTPS proxy, TLS terminator, X.509 TOFU
2 // manager, WARC/geminispace browser
3 // Copyright (C) 2021-2024 Sergey Matveev <stargrave@stargrave.org>
5 // This program is free software: you can redistribute it and/or modify
6 // it under the terms of the GNU General Public License as published by
7 // the Free Software Foundation, version 3 of the License.
9 // This program is distributed in the hope that it will be useful,
10 // but WITHOUT ANY WARRANTY; without even the implied warranty of
11 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 // GNU General Public License for more details.
14 // You should have received a copy of the GNU General Public License
15 // along with this program. If not, see <http://www.gnu.org/licenses/>.
27 "github.com/miekg/dns"
32 func DANE(addr string, cert *x509.Certificate) (bool, bool) {
36 host, port, err := SplitHostPort(addr)
38 log.Printf("can not split host+port: %s: %+v\n", addr, err)
45 m.SetQuestion(dns.Fqdn(fmt.Sprintf("_%s._tcp.%s", port, host)), dns.TypeTLSA)
46 msg, err := dns.Exchange(m, DNSSrv)
48 log.Printf("DNS: %+v\n", err)
51 if msg.MsgHdr.Rcode != dns.RcodeSuccess {
55 for _, answer := range msg.Answer {
56 tlsa, ok := answer.(*dns.TLSA)
66 switch tlsa.Selector {
70 toMatch = cert.RawSubjectPublicKeyInfo
73 switch tlsa.MatchingType {
77 our := sha256.Sum256(toMatch)
80 our := sha512.Sum512(toMatch)
83 if tlsa.Certificate == hex.EncodeToString(hsh) {