Posted Sunday, June 2, 2024
2yElliptical Curves + AES over an HTTPS Websocket
I'm working on this pet project but I have no one to talk seriously about it. So I thought about sharing it here as a letter in a bottle. I work with a complex ever changing (growing?) IT environment. Is hard to get track of infrastructure and most of the time things end up in the team gathering information on spread sheets. As much as I love Opensource, Security has always been a concern for me, so anything that gets into ALL production servers needs to be industry tested, license flexible (as procurement process are always a pain in the...) so most of the time, security is based on a multilayered solution. Lots of cmdb solutions get short on security or functionality side, so I finally tough it will be fun to try and design something from scratch and golang. The solution should have a client-server approach, take advantage of reverse proxy exit architecture and CDN failover. At the same time, client and server should handshake and verify identity. Son far I managed to set up as the title describes a TLS Websocket that transverses exit reverse proxy, CDN, local reverse proxy and server. Makes the tunneled ecc handshake, agrees on an AES key and wraps gin framework on server. It still needs a lot of work in error handling and performance checks. Is there anyone to need talk about it?
Technology Community
The technology community, chat, and discussion.
4.9M SOULS
No comments yet!
Meet New People
50,000,000+
DOWNLOADS