-
Notifications
You must be signed in to change notification settings - Fork 6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
🌐 Open Online Config 1 with Shadowsocks registration #1
Conversation
/cc @fortuna |
Since HTTPS is mandatory, HSTS should be recommended, and the domain name should be added to the HSTS preload list. So that to prevent accidental use of HTTP to access URLs causing secret and userId exposure. |
The remotely issued A example:
|
I'm also removing the restriction on the use of certificate pinning. Sometimes it can be useful to pin publicly-trusted certificates too. |
@mzz2017 Thank you so much for the review suggestions! They have been addressed in the new changes. |
Open Online Config 1 is an HTTPS-based application protocol for the distribution of censorship circumvention services. The protocol aims to provide a centralized model for the sharing of distributed censorship circumvention services in a community.
Open Online Config 1 supersedes SIP008 (standard document, tracking issue) and SIP008ext.
Feel free to review and post suggestions! 😊
Quick Links
Open Questions
301 Moved Permanently
?