import { SocketConfig } from './sockopt'; /** * TLS configuration for Xray-Core. * * @see https://xtls.github.io/en/config/transport.html#tlsobject */ export interface TLSConfig { /** Server Name Indication for TLS handshake. */ serverName?: string; /** ALPN protocols (e.g. ["h2", "http/1.1"]). */ alpn?: string[]; /** Allow insecure TLS connections (skip certificate verification). */ allowInsecure?: boolean; /** TLS certificates. */ certificates?: TLSCertConfig[]; /** Enable TLS session resumption. */ enableSessionResumption?: boolean; /** Disable loading system root CA certificates. */ disableSystemRoot?: boolean; /** Minimum TLS version (e.g. "1.2", "1.3"). */ minVersion?: string; /** Maximum TLS version (e.g. "1.2", "1.3"). */ maxVersion?: string; /** Cipher suites (colon-separated, e.g. "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"). */ cipherSuites?: string; /** uTLS fingerprint for client hello. */ fingerprint?: TLSFingerprint; /** Reject connections with unknown/empty SNI on server side. */ rejectUnknownSni?: boolean; /** Preferred elliptic curves. */ curvePreferences?: string[]; /** Path to write TLS master key log (for debugging, e.g. with Wireshark). */ masterKeyLog?: string; /** SHA-256 hash of pinned peer certificate for certificate pinning. */ pinnedPeerCertSha256?: string; /** Verify peer certificate by exact CN/SAN name. */ verifyPeerCertByName?: string; /** Verify peer certificate against multiple names. */ verifyPeerCertInNames?: string[]; /** ECH server keys (base64, server-side). */ echServerKeys?: string; /** ECH config list (base64, client-side). */ echConfigList?: string; /** ECH force query for config list retrieval. */ echForceQuery?: string; /** Socket options for ECH DNS queries. */ echSockopt?: SocketConfig; } export interface TLSCertConfig { /** Path to certificate file. */ certificateFile?: string; /** Inline certificate content (PEM lines as array). */ certificate?: string[]; /** Path to private key file. */ keyFile?: string; /** Inline private key content (PEM lines as array). */ key?: string[]; /** Certificate usage type. */ usage?: CertificateUsage; /** OCSP stapling update interval in seconds. */ ocspStapling?: number; /** Load certificate only once (no hot-reload). */ oneTimeLoading?: boolean; /** Build full certificate chain. */ buildChain?: boolean; } export type CertificateUsage = 'encipherment' | 'verify' | 'issue' | 'verifyclient'; export type TLSFingerprint = '' | 'chrome' | 'firefox' | 'safari' | 'ios' | 'android' | 'edge' | 'qq' | '360' | 'random' | 'randomized' | 'helloChrome_Auto' | 'helloFirefox_Auto' | 'helloSafari_Auto' | 'helloEdge_Auto' | 'hello360_Auto' | 'helloQQ_Auto'; //# sourceMappingURL=tls.d.ts.map