|
@@ -928,3 +928,316 @@ func TestSimpleTLSConnectionPinned(t *testing.T) {
|
|
|
t.Fatal(err)
|
|
|
}
|
|
|
}
|
|
|
+
|
|
|
+func TestSimpleTLSConnectionPinnedWrongCert(t *testing.T) {
|
|
|
+ tcpServer := tcp.Server{
|
|
|
+ MsgProcessor: xor,
|
|
|
+ }
|
|
|
+ dest, err := tcpServer.Start()
|
|
|
+ common.Must(err)
|
|
|
+ defer tcpServer.Close()
|
|
|
+ certificateDer := cert.MustGenerate(nil)
|
|
|
+ certificate := tls.ParseCertificate(certificateDer)
|
|
|
+ certHash := tls.GenerateCertChainHash([][]byte{certificateDer.Certificate})
|
|
|
+ certHash[1] += 1
|
|
|
+ userID := protocol.NewID(uuid.New())
|
|
|
+ serverPort := tcp.PickPort()
|
|
|
+ serverConfig := &core.Config{
|
|
|
+ Inbound: []*core.InboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
|
|
|
+ PortList: &net.PortList{Range: []*net.PortRange{net.SinglePortRange(serverPort)}},
|
|
|
+ Listen: net.NewIPOrDomain(net.LocalHostIP),
|
|
|
+ StreamSettings: &internet.StreamConfig{
|
|
|
+ SecurityType: serial.GetMessageType(&tls.Config{}),
|
|
|
+ SecuritySettings: []*serial.TypedMessage{
|
|
|
+ serial.ToTypedMessage(&tls.Config{
|
|
|
+ Certificate: []*tls.Certificate{certificate},
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ ProxySettings: serial.ToTypedMessage(&inbound.Config{
|
|
|
+ User: []*protocol.User{
|
|
|
+ {
|
|
|
+ Account: serial.ToTypedMessage(&vmess.Account{
|
|
|
+ Id: userID.String(),
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ Outbound: []*core.OutboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }
|
|
|
+
|
|
|
+ clientPort := tcp.PickPort()
|
|
|
+ clientConfig := &core.Config{
|
|
|
+ Inbound: []*core.InboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
|
|
|
+ PortList: &net.PortList{Range: []*net.PortRange{net.SinglePortRange(clientPort)}},
|
|
|
+ Listen: net.NewIPOrDomain(net.LocalHostIP),
|
|
|
+ }),
|
|
|
+ ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
|
|
|
+ Address: net.NewIPOrDomain(dest.Address),
|
|
|
+ Port: uint32(dest.Port),
|
|
|
+ NetworkList: &net.NetworkList{
|
|
|
+ Network: []net.Network{net.Network_TCP},
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ Outbound: []*core.OutboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ProxySettings: serial.ToTypedMessage(&outbound.Config{
|
|
|
+ Receiver: []*protocol.ServerEndpoint{
|
|
|
+ {
|
|
|
+ Address: net.NewIPOrDomain(net.LocalHostIP),
|
|
|
+ Port: uint32(serverPort),
|
|
|
+ User: []*protocol.User{
|
|
|
+ {
|
|
|
+ Account: serial.ToTypedMessage(&vmess.Account{
|
|
|
+ Id: userID.String(),
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
|
|
|
+ StreamSettings: &internet.StreamConfig{
|
|
|
+ SecurityType: serial.GetMessageType(&tls.Config{}),
|
|
|
+ SecuritySettings: []*serial.TypedMessage{
|
|
|
+ serial.ToTypedMessage(&tls.Config{
|
|
|
+ AllowInsecure: true,
|
|
|
+ PinnedPeerCertificateChainSha256: [][]byte{certHash},
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }
|
|
|
+
|
|
|
+ servers, err := InitializeServerConfigs(serverConfig, clientConfig)
|
|
|
+ common.Must(err)
|
|
|
+ defer CloseAllServers(servers)
|
|
|
+
|
|
|
+ if err := testTCPConn(clientPort, 1024, time.Second*20)(); err == nil {
|
|
|
+ t.Fatal(err)
|
|
|
+ }
|
|
|
+}
|
|
|
+
|
|
|
+func TestUTLSConnectionPinned(t *testing.T) {
|
|
|
+ tcpServer := tcp.Server{
|
|
|
+ MsgProcessor: xor,
|
|
|
+ }
|
|
|
+ dest, err := tcpServer.Start()
|
|
|
+ common.Must(err)
|
|
|
+ defer tcpServer.Close()
|
|
|
+ certificateDer := cert.MustGenerate(nil)
|
|
|
+ certificate := tls.ParseCertificate(certificateDer)
|
|
|
+ certHash := tls.GenerateCertChainHash([][]byte{certificateDer.Certificate})
|
|
|
+ userID := protocol.NewID(uuid.New())
|
|
|
+ serverPort := tcp.PickPort()
|
|
|
+ serverConfig := &core.Config{
|
|
|
+ Inbound: []*core.InboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
|
|
|
+ PortList: &net.PortList{Range: []*net.PortRange{net.SinglePortRange(serverPort)}},
|
|
|
+ Listen: net.NewIPOrDomain(net.LocalHostIP),
|
|
|
+ StreamSettings: &internet.StreamConfig{
|
|
|
+ SecurityType: serial.GetMessageType(&tls.Config{}),
|
|
|
+ SecuritySettings: []*serial.TypedMessage{
|
|
|
+ serial.ToTypedMessage(&tls.Config{
|
|
|
+ Certificate: []*tls.Certificate{certificate},
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ ProxySettings: serial.ToTypedMessage(&inbound.Config{
|
|
|
+ User: []*protocol.User{
|
|
|
+ {
|
|
|
+ Account: serial.ToTypedMessage(&vmess.Account{
|
|
|
+ Id: userID.String(),
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ Outbound: []*core.OutboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }
|
|
|
+
|
|
|
+ clientPort := tcp.PickPort()
|
|
|
+ clientConfig := &core.Config{
|
|
|
+ Inbound: []*core.InboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
|
|
|
+ PortList: &net.PortList{Range: []*net.PortRange{net.SinglePortRange(clientPort)}},
|
|
|
+ Listen: net.NewIPOrDomain(net.LocalHostIP),
|
|
|
+ }),
|
|
|
+ ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
|
|
|
+ Address: net.NewIPOrDomain(dest.Address),
|
|
|
+ Port: uint32(dest.Port),
|
|
|
+ NetworkList: &net.NetworkList{
|
|
|
+ Network: []net.Network{net.Network_TCP},
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ Outbound: []*core.OutboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ProxySettings: serial.ToTypedMessage(&outbound.Config{
|
|
|
+ Receiver: []*protocol.ServerEndpoint{
|
|
|
+ {
|
|
|
+ Address: net.NewIPOrDomain(net.LocalHostIP),
|
|
|
+ Port: uint32(serverPort),
|
|
|
+ User: []*protocol.User{
|
|
|
+ {
|
|
|
+ Account: serial.ToTypedMessage(&vmess.Account{
|
|
|
+ Id: userID.String(),
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
|
|
|
+ StreamSettings: &internet.StreamConfig{
|
|
|
+ SecurityType: serial.GetMessageType(&tls.Config{}),
|
|
|
+ SecuritySettings: []*serial.TypedMessage{
|
|
|
+ serial.ToTypedMessage(&tls.Config{
|
|
|
+ Fingerprint: "random",
|
|
|
+ AllowInsecure: true,
|
|
|
+ PinnedPeerCertificateChainSha256: [][]byte{certHash},
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }
|
|
|
+
|
|
|
+ servers, err := InitializeServerConfigs(serverConfig, clientConfig)
|
|
|
+ common.Must(err)
|
|
|
+ defer CloseAllServers(servers)
|
|
|
+
|
|
|
+ if err := testTCPConn(clientPort, 1024, time.Second*20)(); err != nil {
|
|
|
+ t.Fatal(err)
|
|
|
+ }
|
|
|
+}
|
|
|
+
|
|
|
+func TestUTLSConnectionPinnedWrongCert(t *testing.T) {
|
|
|
+ tcpServer := tcp.Server{
|
|
|
+ MsgProcessor: xor,
|
|
|
+ }
|
|
|
+ dest, err := tcpServer.Start()
|
|
|
+ common.Must(err)
|
|
|
+ defer tcpServer.Close()
|
|
|
+ certificateDer := cert.MustGenerate(nil)
|
|
|
+ certificate := tls.ParseCertificate(certificateDer)
|
|
|
+ certHash := tls.GenerateCertChainHash([][]byte{certificateDer.Certificate})
|
|
|
+ certHash[1] += 1
|
|
|
+ userID := protocol.NewID(uuid.New())
|
|
|
+ serverPort := tcp.PickPort()
|
|
|
+ serverConfig := &core.Config{
|
|
|
+ Inbound: []*core.InboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
|
|
|
+ PortList: &net.PortList{Range: []*net.PortRange{net.SinglePortRange(serverPort)}},
|
|
|
+ Listen: net.NewIPOrDomain(net.LocalHostIP),
|
|
|
+ StreamSettings: &internet.StreamConfig{
|
|
|
+ SecurityType: serial.GetMessageType(&tls.Config{}),
|
|
|
+ SecuritySettings: []*serial.TypedMessage{
|
|
|
+ serial.ToTypedMessage(&tls.Config{
|
|
|
+ Certificate: []*tls.Certificate{certificate},
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ ProxySettings: serial.ToTypedMessage(&inbound.Config{
|
|
|
+ User: []*protocol.User{
|
|
|
+ {
|
|
|
+ Account: serial.ToTypedMessage(&vmess.Account{
|
|
|
+ Id: userID.String(),
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ Outbound: []*core.OutboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ProxySettings: serial.ToTypedMessage(&freedom.Config{}),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }
|
|
|
+
|
|
|
+ clientPort := tcp.PickPort()
|
|
|
+ clientConfig := &core.Config{
|
|
|
+ Inbound: []*core.InboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ReceiverSettings: serial.ToTypedMessage(&proxyman.ReceiverConfig{
|
|
|
+ PortList: &net.PortList{Range: []*net.PortRange{net.SinglePortRange(clientPort)}},
|
|
|
+ Listen: net.NewIPOrDomain(net.LocalHostIP),
|
|
|
+ }),
|
|
|
+ ProxySettings: serial.ToTypedMessage(&dokodemo.Config{
|
|
|
+ Address: net.NewIPOrDomain(dest.Address),
|
|
|
+ Port: uint32(dest.Port),
|
|
|
+ NetworkList: &net.NetworkList{
|
|
|
+ Network: []net.Network{net.Network_TCP},
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ Outbound: []*core.OutboundHandlerConfig{
|
|
|
+ {
|
|
|
+ ProxySettings: serial.ToTypedMessage(&outbound.Config{
|
|
|
+ Receiver: []*protocol.ServerEndpoint{
|
|
|
+ {
|
|
|
+ Address: net.NewIPOrDomain(net.LocalHostIP),
|
|
|
+ Port: uint32(serverPort),
|
|
|
+ User: []*protocol.User{
|
|
|
+ {
|
|
|
+ Account: serial.ToTypedMessage(&vmess.Account{
|
|
|
+ Id: userID.String(),
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ SenderSettings: serial.ToTypedMessage(&proxyman.SenderConfig{
|
|
|
+ StreamSettings: &internet.StreamConfig{
|
|
|
+ SecurityType: serial.GetMessageType(&tls.Config{}),
|
|
|
+ SecuritySettings: []*serial.TypedMessage{
|
|
|
+ serial.ToTypedMessage(&tls.Config{
|
|
|
+ Fingerprint: "random",
|
|
|
+ AllowInsecure: true,
|
|
|
+ PinnedPeerCertificateChainSha256: [][]byte{certHash},
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }),
|
|
|
+ },
|
|
|
+ },
|
|
|
+ }
|
|
|
+
|
|
|
+ servers, err := InitializeServerConfigs(serverConfig, clientConfig)
|
|
|
+ common.Must(err)
|
|
|
+ defer CloseAllServers(servers)
|
|
|
+
|
|
|
+ if err := testTCPConn(clientPort, 1024, time.Second*20)(); err == nil {
|
|
|
+ t.Fatal(err)
|
|
|
+ }
|
|
|
+}
|