diff --git a/listener/inbound/vmess_interop_test.go b/listener/inbound/vmess_interop_test.go index 190e68a6..0ee74045 100644 --- a/listener/inbound/vmess_interop_test.go +++ b/listener/inbound/vmess_interop_test.go @@ -3,7 +3,10 @@ package inbound_test import ( "bytes" "context" + "crypto/sha256" + "encoding/base64" "encoding/json" + "encoding/pem" "errors" "fmt" "io" @@ -396,3 +399,22 @@ func vmessInteropPort(addr string) string { _, port, _ := net.SplitHostPort(addr) return port } + +func vmessInteropCertChainHash(certContent []byte) string { + var hashValue []byte + for { + block, remain := pem.Decode(certContent) + if block == nil { + break + } + certHash := sha256.Sum256(block.Bytes) + if hashValue == nil { + hashValue = certHash[:] + } else { + chainHash := sha256.Sum256(append(hashValue, certHash[:]...)) + hashValue = chainHash[:] + } + certContent = remain + } + return base64.StdEncoding.EncodeToString(hashValue) +} diff --git a/listener/inbound/vmess_mekya_interop_test.go b/listener/inbound/vmess_mekya_interop_test.go index 59bc63dc..62a63b7b 100644 --- a/listener/inbound/vmess_mekya_interop_test.go +++ b/listener/inbound/vmess_mekya_interop_test.go @@ -218,7 +218,7 @@ func mekyaInteropServerSecuritySettings(certFile, keyFile string) map[string]any func mekyaInteropClientSecuritySettings() map[string]any { return map[string]any{ - "pinnedPeerCertificateChainSha256": []string{tlsMirrorInteropCertChainHash([]byte(tlsCertificate))}, + "pinnedPeerCertificateChainSha256": []string{vmessInteropCertChainHash([]byte(tlsCertificate))}, "allowInsecureIfPinnedPeerCertificate": true, } } diff --git a/listener/inbound/vmess_tlsmirror_interop_test.go b/listener/inbound/vmess_tlsmirror_interop_test.go index acf5d081..fe7d780f 100644 --- a/listener/inbound/vmess_tlsmirror_interop_test.go +++ b/listener/inbound/vmess_tlsmirror_interop_test.go @@ -3,9 +3,6 @@ package inbound_test import ( "bufio" "context" - "crypto/sha256" - "encoding/base64" - "encoding/pem" "fmt" "io" "net" @@ -451,29 +448,10 @@ func startTLSMirrorInteropCarrierTLS(t *testing.T, configure ...func(*tls.Config return tlsMirrorInteropCarrier{ addr: ln.Addr().String(), fingerprint: fingerprint, - certChainHash: tlsMirrorInteropCertChainHash([]byte(certPEM)), + certChainHash: vmessInteropCertChainHash([]byte(certPEM)), } } -func tlsMirrorInteropCertChainHash(certContent []byte) string { - var hashValue []byte - for { - block, remain := pem.Decode(certContent) - if block == nil { - break - } - certHash := sha256.Sum256(block.Bytes) - if hashValue == nil { - hashValue = certHash[:] - } else { - chainHash := sha256.Sum256(append(hashValue, certHash[:]...)) - hashValue = chainHash[:] - } - certContent = remain - } - return base64.StdEncoding.EncodeToString(hashValue) -} - func startTLSMirrorInteropCarrierHTTP2(t *testing.T) tlsMirrorInteropCarrier { t.Helper() certPEM, keyPEM, fingerprint, err := ca.NewRandomTLSKeyPair(ca.KeyPairTypeP256) @@ -501,6 +479,6 @@ func startTLSMirrorInteropCarrierHTTP2(t *testing.T) tlsMirrorInteropCarrier { return tlsMirrorInteropCarrier{ addr: ln.Addr().String(), fingerprint: fingerprint, - certChainHash: tlsMirrorInteropCertChainHash([]byte(certPEM)), + certChainHash: vmessInteropCertChainHash([]byte(certPEM)), } }