Meta tags:
description= Every byte of a QUIC connection explained and reproduced;
Headings (most frequently used words):
the, quic, illustrated, connection, every, byte, explained, and, reproduced, is, secure, udp, based, stream, protocol, that, forms, basis, of, http,
Text of the page (most frequently used words):
the (1194), packet (358), this (340), bytes (273), key (253), data (223), number (216), and (208), header (207), for (189), byte (182), client (166), server (163), length (140), handshake (130), connection (128), protection (121), that (117), with (117), from (115), bits (101), value (95), has (81), integer (76), first (75), follows (75), tls (73), quic (73), one (67), field (66), which (65), keys (65), are (60), initial (60), variable (58), frame (56), assigned (56), encrypted (55), two (55), packets (54), label (54), application (52), stream (52), extension (52), hkdf (50), calc (49), xor (48), sample (48), type (46), will (44), then (43), given (43), sent (42), used (42), step (40), openssl (40), record (38), version (38), not (37), indicates (37), decryption (36), aes_128_gcm_decrypt (36), applied (36), each (36), below (36), also (35), can (35), command (35), line (35), traffic (34), because (33), certificate (32), into (31), ack (31), meaning (30), crypto (30), using (29), algorithm (29), between (29), example (29), always (29), indicate (29), payload (28), how (28), xxd (28), len (28), expand (27), public (27), numbers (26), format (26), have (26), echo (26), ctx (26), see (25), details (25), than (25), information (25), following (25), sha256 (25), giving (24), ing (24), case (24), aead (24), recdata (24), authtag (24), recordnum (24), tag (24), unprotected (24), truncated (24), endpoint (24), spread (24), seen (24), disable (24), network (24), lower (24), being (24), exchange (24), sends (23), destination (23), was (23), sending (22), remaining (22), encryption (21), private (21), tool (20), tmp (20), bit (20), protocol (20), only (19), message (19), must (18), does (18), cat (18), indicating (18), more (18), process (17), support (17), its (17), result (17), offset (17), starts (17), hash (17), versions (17), signature (17), add (16), flags (16), encrypt (16), begins (16), observers (16), such (16), later (16), set (16), above (16), many (16), source (16), long (16), finished (16), list (16), supported (16), hexdump (15), conversation (15), address (15), all (15), datagram (15), provided (15), follow (15), session (15), random (15), input (14), need (14), include (14), full (14), allows (14), sender (14), other (14), acknowledged (14), largest_acknowledged (14), contains (14), may (13), generated (13), during (13), yet (13), tools (13), confirms (13), calculates (13), highest (13), based (13), hide (13), encrypting (13), certain (13), protected (13), fixed (13), taken (13), ack_delay_exponent (13), client_secret (13), server_secret (13), extensions (13), were (12), modified (12), takes (12), beginning (12), authenticated (12), match (12), succeed (12), ciphers (12), written (12), both (12), lib (12), dirs (12), lssl (12), lcrypto (12), msg1 (12), 00000000 (12), decrypt (12), authentication (12), integrity (12), produced (12), consumed (12), auth (12), potentially (12), lowest (12), unacknowledged (12), doubles (12), safety (12), rounds (12), figures (12), remove (12), high (12), unambiguously (12), represent (12), those (12), ends (12), encoded (12), receiving (12), fills (12), most (12), recently (12), our (12), few (12), fewer (12), truncation (12), won (12), occur (12), document (12), rfc (12), 9000 (12), same (12), c_cid (12), outside (12), resulting (12), sections (12), compute (12), lsb (12), reserved (12), unset (12), msb (12), val (12), starting (12), past (12), aes (12), 128 (12), ecb (12), head (12), give (12), hello (12), optionally (11), amount (11), clienthello (11), recognized (10), recipients (10), even (10), nat (10), translation (10), changed (10), making (10), resilient (10), underlying (10), s_cid (10), single (10), 0x4 (10), expandlabel (10), represented (10), calculation (10), size (10), curve25519 (10), udp (9), before (9), additional (9), ping (9), point (9), verify (9), token (9), ephemeral (9), x25519 (9), compression (9), found (8), short (8), allow (8), but (8), acknowledges (8), showing (8), 0x00 (8), total (8), detail (8), created (8), extract (8), padding (8), 1200 (8), parameters (8), alpn (8), receipt (7), first_ack_range (7), ranges (7), ack_range_count (7), time (7), delayed (7), microseconds (7), multiply (7), µseconds (7), ack_delay (7), largest (7), there (7), containing (7), frames (7), create (7), perform (7), without (7), snip (7), 256 (7), rest (7), serverhello (7), generation (7), certificateverify (7), negotiation (7), chosen (7), name (7), share (7), cipher (7), rsa (7), 00000010 (6), 0x01 (6), own (6), library (6), directional (6), use (6), headers (6), secure (6), values (6), uses (6), handshake_hash (6), secret (6), these (6), empty_hash (6), salt (6), much (6), larger (6), any (6), mtu (6), higher (6), where (6), curve (6), mult (6), generating (6), tosign (6), provides (6), new (6), initial_max_streams_uni (6), initial_max_streams_bidi (6), 524288 (6), initial_max_stream_data_uni (6), initial_max_stream_data_bidi_remote (6), initial_max_stream_data_bidi_local (6), initial_max_data (6), max_udp_payload_size (6), transport (6), instead (6), explained (6), 1048576 (6), including (5), second (5), know (5), encoding (5), unused (5), pong (5), last (5), binary (5), 17abbf0a788f96c6986964660414e7ec (5), 09597a2ea3b04c00487e71f3 (5), 0xe0 (5), 2a18061c396c2828582b41b0910ed536 (5), every (5), crypto_clienthello (5), crypto_serverhello (5), messages (5), establish (5), operations (5), handshake_secret (5), send (5), small (5), responses (5), some (5), host (5), b14b918124fda5c8d79847602fa3520b (5), ddbc15dea80925a55686a7df (5), here (5), 6df4e9d737cdf714711d7c617ee82981 (5), shared (5), previous (5), string (5), provide (5), certificates (5), request (5), hostname (5), initial_source_connection_id (5), middleboxes (5), selected (5), modes (5), algorithms (5), http (5), fd8c7da9de1b2da4d2ef9fd5188922d0 (4), 02f6180e4f4aa456d7e8a602 (4), note (4), peer (4), either (4), embedding (4), 0x40 (4), phase (4), signal (4), when (4), rotation (4), occurs (4), spin (4), measure (4), rtt (4), b7f6f021453e52b58940e4bba72a35d4 (4), received (4), e010a295f0c2864f186b2a7e8fdc9ed7 (4), eb3fbc384a3199dcf6b4c808 (4), 8a6a38bc5cc40cb482a254dac68c9d2f (4), gives (4), increase (4), opened (4), whether (4), 0x1 (4), 0x2 (4), bitmask (4), final (4), done (4), present (4), otherwise (4), third (4), verify_data (4), built (4), fin_hash (4), crypto_extensions (4), crypto_cert (4), fin_key (4), hmac (4), finished_key (4), finished_hash (4), 0x20 (4), verification (4), 30a7e816f6a1e1b3434cf39cf4b415e7 (4), 11e70a5d1361795d2bb04465 (4), 84b3c21cacaf9f54c885e9a506459079 (4), calculate (4), performs (4), derivation (4), attacks (4), get (4), derived_secret (4), attack (4), servers (4), limit (4), minimum (4), vast (4), majority (4), networks (4), padded (4), prove (4), end (4), path (4), agree (4), calculated (4), reproduced (4), null (4), pub (4), pss (4), been (4), pre (4), explanation (4), grease (4), technique (4), 65527 (4), 0001020304050607 (4), layer (4), hello_hash (4), method (4), suite (4), d77fc4056fcfa32bd1302469ee6ebf90 (4), fcb748e37ff79860faa07477 (4), 440b2725e91dc79b370711ef792faa3d (4), site (4), psk (4), pkcs1 (4), csecret (4), ssecret (4), material (4), code (3), shutdown (3), error (3), confirmed (3), about (3), three (3), content (3), reply (3), 0x16 (3), find (3), excluding (3), crypto_certverify (3), dgst (3), 0x14 (3), creates (3), 0x24 (3), finds (3), now (3), known (3), b965185af5034eda0ea13ab424dde193afcb42451823a96921ae9d2dad9594ef (3), zero_key (3), derived (3), master_secret (3), client_key (3), server_key (3), client_iv (3), server_iv (3), party (3), would (3), cause (3), forbidden (3), replying (3), until (3), once (3), needed (3), 0xc0 (3), 0000000 (3), 0000010 (3), df4a291baa1eb7cfa6934b29b474baad2697e29f1f920dcc77c8a0a088447624 (3), copy (3), noout (3), records (3), der (3), page (3), context (3), them (3), 0x80000 (3), max_idle_timeout (3), original_destination_connection_id (3), next (3), ff788f9ed09e60d8142ac10a8931cdb6a3726278d3acdba54d9d9ffc7326611b (3), early_secret (3), negotiated (3), take (3), made (3), deployed (3), they (3), longer (3), able (3), 0x100000 (3), supports (3), order (3), preference (3), rsae (3), sha384 (3), groups (3), entry (3), suites (3), 38762cf7f55934b34d179ae6a4c80cadccbb7f0a (3), init_secret (3), initial_secret (3), you (2), indication (2), close (2), reason (2), graceful (2), connection_close (2), acks (2), sequentially (2), direction (2), uni (2), streams (2), mechanism (2), analogous (2), individual (2), tcp (2), range (2), 0x8 (2), through (2), 0xf (2), 0b00001xxx (2), acting (2), fin (2), writing (2), consume (2), off (2), handshake_done (2), post (2), 0x02 (2), contents (2), reproduce (2), crypto_s_finished (2), cht_secret (2), mac (2), macopt (2), hexkey (2), msg (2), successful (2), tampered (2), confirm (2), shown (2), feed (2), designed (2), protect (2), against (2), possible (2), 0000000000000000000000000000000000000000000000000000000000000000 (2), client_hp_key (2), server_hp_key (2), serves (2), purposes (2), class (2), attacker (2), innocent (2), replies (2), directed (2), target (2), could (2), spoofing (2), datagrams (2), help (2), mitigate (2), times (2), proof (2), round (2), trip (2), originally (2), adding (2), budget (2), exceeding (2), amplification (2), mitigation (2), ipv4 (2), router (2), allowed (2), drop (2), exceed (2), their (2), 576 (2), internet (2), typically (2), 1500 (2), throughput (2), performance (2), realities (2), chooses (2), constraint (2), should (2), traverse (2), real (2), tunneled (2), dropped (2), prevent (2), scenario (2), established (2), successfully (2), smaller (2), timing (2), out (2), validation (2), appending (2), nul (2), multiplies (2), elliptic (2), multiplication (2), since (2), sht_secret (2), signs (2), signing (2), sig (2), x509 (2), crt (2), sigopt (2), fragment (2), 0x3ff (2), 1023 (2), continues (2), another (2), empty (2), optional (2), configuration (2), listing (2), preventing (2), disallowing (2), reserving (2), injecting (2), randomly (2), connections (2), 5242880 (2), 0xfff7 (2), negotiate (2), protocols (2), 0xb (2), 0x56 (2), listed (2), encryptedextensions (2), ivs (2), shared_secret (2), unlike (2), clear (2), via (2), options (2), tls_aes_128_gcm_sha256 (2), legacy (2), predictable (2), widely (2), recognize (2), sessions (2), performed (2), unusual (2), representing (2), due (2), minor (2), revision (2), ssl (2), therefore (2), back (2), continue (2), requires (2), pkey (2), text (2), priv (2), doesn (2), understood (2), depth (2), selecting (2), keypair (2), parties (2), eavesdropper (2), tell (2), what (2), put (2), 0xa (2), 10485760 (2), available (2), psks (2), after (2), presented (2), descending (2), sha512 (2), ecdsa (2), secp384r1 (2), secp256r1 (2), cryptography (2), types (2), curves (2), followed (2), read (2), methods (2), requested (2), begin (2), cryptographic (2), google (2), over (2), init_salt (2), init_dcid (2), client_init_key (2), server_init_key (2), client_init_iv (2), server_init_iv (2), client_init_hp (2), server_init_hp (2), ckey (2), civ (2), chp (2), skey (2), siv (2), shp (2), initial_salt (2), initial_random (2), illustrated (2), print, annotations, show, interested, breakdown, project, captures, github, 0x11, triggered, unknown, 40635f63696401, 688be9fd7b302d9eb47cdf1fc4cd9aac, shu, tdown, ffeb17b67ec27f97e50d271dc702d92c, f494fdfbb6, having, pending, shuts, down, 40735f63696401, 8b44b10d7cd32b03e34502802f25a193, 90588b44b10d7cd32b03e34502802f25, 1ac9ce3a7a0, complete, 144, 40635f63696400, ea6e3a21faaf99af2fe10321692057d2, 4057c883e94d9c296baa8ca0ea6e3a21, 09cd79a059, 224, e00000000105635f63696405735f636964401602, 6f1b817e4623e1acbe1db3899b00ecfb, 169e6f1b817e4623e1acbe1db3899b00, a5a6f88ece, 40735f63696400, 8b8ed10cba39a06ab7b0670a50ef68e6, e66e8ee950ba8b8ed10cba39a06ab7b0, 4e1e62a65d, b8902ab5f9fe52fdec3aea54e9293e4b8eabf955fcd88536bf44b8b584f14982, 50ffb0c1a425c641891c983d126726026d3db28ea3510bdc2054fcd637edcacc, serverfinished, 560, e00000000105735f63696405635f636964403f01, 5e98f22dc6f25979919bad302f448c0a, 00000020, 0x3f, 9da7e61daa07732aa10b5fbd11a00a62, b0b3b06690, completing, fb9fc80689b3a5d02c33243bf69a1b1b20705588a794304a6e7120155edf149a, serverhandshakefinished, e00000000105735f63696405635f636964401600, 12512d7eda141ec057b804d30feb515b, c6cc12512d7eda141ec057b804d30feb, 5e8c3ee850, 129, 032, c00000000105735f63696405635f63696400401701, 0555cdb783fbdf5b52724b7d29f0afe3, 0x17, ed1f7b0555cdb783fbdf5b52724b7d29, 8f57c29e79, properties, identical, 88ad8d3b0986a71965a28d108b0f40ffffe629284a6028c80ddc5dc083b3f5d1, 068fcb606aa1c8aa354d7b6064a3328cf376bcd9f3200e68ace3de2ee9fcaccb, inherently, tied, owns, validity, associated, proven, valid, included, introduces, changing, wrapped, trailers, build, signed, space, characters, character, want, pubkey, rsa_padding_mode, rsa_pss_saltlen, verified, 0x100, rsa_pss_rsae_sha256, 0x104, 260, 0x0f, ties, ownership, remainder, 0xb9, 185, e00000000105635f63696405735f63696440cf01, 2ed1025f98fea6d6024998184687dc06, 0xcf, 207, 19681c3f0f102a30f5e647a3399abf54, e54e8fcd38, asn, documented, converted, outform, 0x325, 805, 0x32a, 810, response, 0x32e, 814, 0x0b, effort, keep, called, explore, further, form, chain, trust, leading, trusted, installed, asserting, owner, holds, 0x500000, 0x1d4c0, 120000, 0x41, 120000ms, minutes, option, 0x54, 0x08, aren, negotiating, eavesdroppers, part, e00000000105635f63696405735f636964441400, 8ffb53316d673a32b89259b5d33e94ad, 0x414, 1044, 296209dff2d02d3d50af692176dd4d50, ddb7ce7613, returned, did, knows, understand, 0x2e, 0x1301, says, 0x5a, 512, c00000000105635f63696405735f63696400407500, f0b517a926d62a54a9294136b143b033, pqrstuvwxyz, 0x75, 117, repeated, d5d9c823d07c616882ca770279249864, 4d3acc3988, responds, return, gets, computes, 9fd7ad6dcff4298dd3f96d5b1b2af910a0535b1488d7f8fabb349a982880b615, 909192939495969798999a9b9c9d9e9fa0a1a2a3a4a5a6a7a8a9aaabacadaeaf, tampering, malicious, actors, 0x19, 0xa00000, 0x31, compatibility, reasons, establishing, effect, dhe, establishment, thinks, 0x26, influence, presents, well, sha1, 0x12, applications, might, indicated, make, generic, calls, group, contacting, sni, https, service, multiple, hostnames, virtual, hosts, couldn, ulfheim, net, 0x13, dns, 0x18, action, enable, features, start, 0xbb, 187, leak, allowing, change, crime, ordered, preferred, tls_chacha20_poly1305_sha256, tls_aes_256_gcm_sha384, 0xea, 234, saying, 0xee, 238, c00000000108000102030405060705635f63696400410300, b3b7241ef6646a6c86e5c62ce08be099, 0x103, 259, scenarios, attempt, spoofed, deriving, ed78716be9711ba498b7ed868443bb2e, ed9895bb15, prepare, place, limited, security, observer, derive, like, prevents, kinds, forgery, derives, magic, constant, interesting, mathematical, constants, principles, sha, collision, discovered, researchers, itself, initially, sponsored, introduced, concepts, still, inputs, entropy, evenly, distributed, output, nothing, 358072d6365880d1aeea329adf9121383851ed21a28e3b75e965d0d2cd166254, 202122232425262728292a2b2c2d2e2f303132333435363738393a3b3c3d3e3f, open, demonstration, connects, negotiates, receives, terminates, click, exploring, forms, basis, dtls,
Text of the page (random words):
any extensions that aren t needed for negotiating encryption keys are listed here to hide them from eavesdroppers and middleboxes tls handshake header 08 00 00 56 each tls handshake message starts with a type and a length 08 handshake message type 0x08 encrypted extensions 00 00 56 0x56 86 bytes of handshake message data follows extensions length 00 54 00 54 0x54 84 bytes of extension data follows extension alpn 00 10 00 0b 00 09 08 70 69 6e 67 2f 31 2e 30 application layer protocol negotiation or alpn is used by quic to negotiate supported protocols and versions between server and client the server indicates it has chosen ping 1 0 for the application protocol it was the only option given by the client 00 10 assigned value for extension application layer protocol negotiation 00 0b 0xb 11 bytes of alpn extension data follows 00 09 9 bytes of alpn protocol data follows 08 8 bytes of a protocol name follows 70 69 2e 30 the string ping 1 0 extension quic transport parameters 00 39 00 41 00 08 00 01 02 03 04 05 06 07 01 04 80 01 d4 c0 03 04 80 00 ff f7 04 04 80 50 00 00 05 04 80 08 00 00 06 04 80 08 00 00 07 04 80 08 00 00 08 01 02 09 01 02 0a 01 03 0b 01 19 0f 05 73 5f 63 69 64 the server s configuration values for the quic connection are given here the following quic parameters are set in the data below original_destination_connection_id 0001020304050607 max_idle_timeout 120000ms 2 minutes max_udp_payload_size 65527 initial_max_data 5242880 initial_max_stream_data_bidi_local 524288 initial_max_stream_data_bidi_remote 524288 initial_max_stream_data_uni 524288 initial_max_streams_bidi 2 initial_max_streams_uni 2 ack_delay_exponent 3 a full listing and explanation of the bytes follows 00 39 assigned value for extension quic transport parameters 00 41 0x41 65 bytes of quic transport parameters extension data follows 00 assigned value for original_destination_connection_id 08 8 bytes of original_destination_connection_id data follows 00 01 06 07 the initial connection id given by the client used for initial keys 01 assigned value for max_idle_timeout 04 4 bytes of max_idle_timeout data follows 80 01 d4 c0 a variable length integer with value 0x1d4c0 120000 03 assigned value for max_udp_payload_size 04 4 bytes of max_udp_payload_size data follows 80 00 ff f7 a variable length integer with value 0xfff7 65527 04 assigned value for initial_max_data 04 4 bytes of initial_max_data data follows 80 50 00 00 a variable length integer with value 0x500000 5242880 05 assigned value for initial_max_stream_data_bidi_local 04 4 bytes of initial_max_stream_data_bidi_local data follows 80 08 00 00 a variable length integer with value 0x80000 524288 06 assigned value for initial_max_stream_data_bidi_remote 04 4 bytes of initial_max_stream_data_bidi_remote data follows 80 08 00 00 a variable length integer with value 0x80000 524288 07 assigned value for initial_max_stream_data_uni 04 4 bytes of initial_max_stream_data_uni data follows 80 08 00 00 a variable length integer with value 0x80000 524288 08 assigned value for initial_max_streams_bidi 01 1 bytes of initial_max_streams_bidi data follows 02 a variable length integer with value 2 09 assigned value for initial_max_streams_uni 01 1 bytes of initial_max_streams_uni data follows 02 a variable length integer with value 2 0a assigned value for ack_delay_exponent 01 1 bytes of ack_delay_exponent data follows 03 a variable length integer with value 3 0b assigned value for grease a technique for preventing middleboxes from disallowing new extensions by pre reserving extension values and injecting them randomly into connections 01 1 bytes of grease data follows 19 a variable length integer with value 25 0f assigned value for initial_source_connection_id 05 5 bytes of initial_source_connection_id data follows 73 5f 63 69 64 a copy of the source connection id from the packet header s_cid tls certificate the server sends one or more certificates the certificate for this host containing the hostname a public key and a signature from a third party asserting that the owner of the certificate s hostname holds the private key for this certificate an optional list of further certificates each of which signs the previous certificate and which form a chain of trust leading from the host certificate to a trusted certificate that has been pre installed on the client in an effort to keep this example small we only send a host certificate certificates are in a binary format called der which you can explore here tls handshake header 0b 00 03 2e each tls handshake message starts with a type and a length 0b handshake message type 0x0b certificate 00 03 2e 0x32e 814 bytes of certificate payload follow request context 00 this record is empty because this certificate was not sent in response to a certificate request 00 0 bytes of request context follows certificates length 00 03 2a 00 03 2a 0x32a 810 bytes of certificates follow certificate length 00 03 25 the length of the first and only certificate 00 03 25 0x325 805 bytes of certificate follows certificate 30 82 03 21 30 82 02 09 a0 03 02 01 02 02 08 15 5a 92 ad c2 04 8f 90 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 22 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 0a 13 0a 45 78 61 6d 70 6c 65 20 43 41 30 1e 17 0d 31 38 31 30 30 35 30 31 33 38 31 37 5a 17 0d 31 39 31 30 30 35 30 31 33 38 31 37 5a 30 2b 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 1c 30 1a 06 03 55 04 03 13 13 65 78 61 6d 70 6c 65 2e 75 6c 66 68 65 69 6d 2e 6e 65 74 30 82 01 22 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 0f 00 30 82 01 0a 02 82 01 01 00 c4 80 36 06 ba e7 47 6b 08 94 04 ec a7 b6 91 04 3f f7 92 bc 19 ee fb 7d 74 d7 a8 0d 00 1e 7b 4b 3a 4a e6 0f e8 c0 71 fc 73 e7 02 4c 0d bc f4 bd d1 1d 39 6b ba 70 46 4a 13 e9 4a f8 3d f3 e1 09 59 54 7b c9 55 fb 41 2d a3 76 52 11 e1 f3 dc 77 6c aa 53 37 6e ca 3a ec be c3 aa b7 3b 31 d5 6c b6 52 9c 80 98 bc c9 e0 28 18 e2 0b f7 f8 a0 3a fd 17 04 50 9e ce 79 bd 9f 39 f1 ea 69 ec 47 97 2e 83 0f b5 ca 95 de 95 a1 e6 04 22 d5 ee be 52 79 54 a1 e7 bf 8a 86 f6 46 6d 0d 9f 16 95 1a 4c f7 a0 46 92 59 5c 13 52 f2 54 9e 5a fb 4e bf d7 7a 37 95 01 44 e4 c0 26 87 4c 65 3e 40 7d 7d 23 07 44 01 f4 84 ff d0 8f 7a 1f a0 52 10 d1 f4 f0 d5 ce 79 70 29 32 e2 ca be 70 1f df ad 6b 4b b7 11 01 f4 4b ad 66 6a 11 13 0f e2 ee 82 9e 4d 02 9d c9 1c dd 67 16 db b9 06 18 86 ed c1 ba 94 21 02 03 01 00 01 a3 52 30 50 30 0e 06 03 55 1d 0f 01 01 ff 04 04 03 02 05 a0 30 1d 06 03 55 1d 25 04 16 30 14 06 08 2b 06 01 05 05 07 03 02 06 08 2b 06 01 05 05 07 03 01 30 1f 06 03 55 1d 23 04 18 30 16 80 14 89 4f de 5b cc 69 e2 52 cf 3e a3 00 df b1 97 b8 1d e1 c1 46 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 03 82 01 01 00 59 16 45 a6 9a 2e 37 79 e4 f6 dd 27 1a ba 1c 0b fd 6c d7 55 99 b5 e7 c3 6e 53 3e ff 36 59 08 43 24 c9 e7 a5 04 07 9d 39 e0 d4 29 87 ff e3 eb dd 09 c1 cf 1d 91 44 55 87 0b 57 1d d1 9b df 1d 24 f8 bb 9a 11 fe 80 fd 59 2b a0 39 8c de 11 e2 65 1e 61 8c e5 98 fa 96 e5 37 2e ef 3d 24 8a fd e1 74 63 eb bf ab b8 e4 d1 ab 50 2a 54 ec 00 64 e9 2f 78 19 66 0d 3f 27 cf 20 9e 66 7f ce 5a e2 e4 ac 99 c7 c9 38 18 f8 b2 51 07 22 df ed 97 f3 2e 3e 93 49 d4 c6 6c 9e a6 39 6d 74 44 62 a0 6b 42 c6 d5 ba 68 8e ac 3a 01 7b dd fc 8e 2c fc ad 27 cb 69 d3 cc dc a2 80 41 44 65 d3 ae 34 8c e0 f3 4a b2 fb 9c 61 83 71 31 2b 19 10 41 64 1c 23 7f 11 a5 d6 5c 84 4f 04 04 84 99 38 71 2b 95 9e d6 85 bc 5c 5d d6 45 ed 19 90 94 73 40 29 26 dc b4 0e 34 69 a1 59 41 e8 e2 cc a8 4b b6 08 46 36 a0 the certificate is in asn 1 der encoding the details of this format and the content of this binary payload are documented on another page the certificate can be converted to the binary data in this message at the command line openssl x509 outform der server crt hexdump 0000000 30 82 03 21 30 82 02 09 a0 03 02 01 02 02 08 15 0000010 5a 92 ad c2 04 8f 90 30 0d 06 09 2a 86 48 86 f7 snip certificate extensions 00 00 the server can provide extension data for the certificate 00 00 0 bytes of extension data follows udp datagram 3 server handshake finished server handshake packet the server continues with another handshake packet this packet contains the rest of the server s tls 1 3 handshake records packet header byte e5 e0 disable header protection the packet begins with a header byte which has header protection applied header protection is used to hide packet numbers and other information from outside observers header protection is applied by encrypting a sample of each packet s payload with the header protection key then xor ing certain bits and bytes in each packet with the resulting data for long format packets such as this one the protected sections are the lower 4 bits of this byte and the bytes of the packet number seen later an example of how to compute header protection server header protection key from calc step above key 2a18061c396c2828582b41b0910ed536 sample is taken from 16 bytes of payload starting 4 bytes past the first byte of the packet number sample 19681c3f0f102a30f5e647a3399abf54 echo sample xxd r p openssl aes 128 ecb k key head c 5 xxd p e54e8fcd38 first byte of result is xor d into lower 4 bits of this byte remaining bytes are xor d one for one into the bytes of the packet number which in this packet is only one byte the bits in the unprotected byte 0xe0 have the following meaning val meaning msb 1 long header format 1 fixed bit always set 10 packet type handshake 00 reserved always unset lsb 00 packet number field length indicates the packet number field below will have length of one byte quic version 00 00 00 01 the version of quic is given version 1 destination connection id 05 63 5f 63 69 64 the destination connection id is given this field allows packets for a connection to be recognized by recipients even if the sender s network address or nat translation has changed making it more resilient than the underlying network connection 05 5 bytes of connection id follows 63 5f 63 69 64 the connection id c_cid source connection id 05 73 5f 63 69 64 the source connection id is given 05 5 bytes of connection id follows 73 5f 63 69 64 the connection id s_cid packet length 40 cf the server indicates how many bytes of packet data follow this field is a variable length integer the first two bits of the first byte indicate how many total bytes are in the integer the first byte starts with the two bits 0 1 0x4 which indicate two bytes the remaining bits give the number 0xcf or 207 bytes packet number 4f 01 disable header protection this byte has header protection applied see packet header byte for details this byte has the unprotected value of 0x01 indicating it is packet 1 or the second handshake packet sent by the server this data is also potentially truncated the sending endpoint calculates the spread between the highest packet number sent and the lowest unacknowledged packet number doubles that spread for safety rounds up then figures the number of bytes it can remove from the high bits of the packet number to unambiguously represent a number between those two ends the encoded packet number is then truncated to that number of bytes and the receiving endpoint fills in the full number based on the packet numbers it has most recently seen because our example conversation sends so few packets fewer than 64 this truncation won t occur in this document see rfc 9000 for details encrypted data 44 20 f9 19 68 1c 3f 0f 10 2a 30 f5 e6 47 a3 39 9a bf 54 bc 8e 80 45 31 34 99 6b a3 30 99 05 62 42 f3 b8 e6 62 bb fc e4 2f 3e f2 b6 ba 87 15 91 47 48 9f 84 79 e8 49 28 4e 98 3f d9 05 32 0a 62 fc 7d 67 e9 58 77 97 09 6c a6 01 01 d0 b2 68 5d 87 47 81 11 78 13 3a d9 17 2b 7f f8 ea 83 fd 81 a8 14 ba e2 7b 95 3a 97 d5 7e bf f4 b4 71 0d ba 8d f8 2a 6b 49 d7 d7 fa 3d 81 79 cb db 86 83 d4 bf a8 32 64 54 01 e5 a5 6a 76 53 5f 71 c6 fb 3e 61 6c 24 1b b1 f4 3b c1 47 c2 96 f5 91 40 29 97 ed 49 aa 0c 55 e3 17 21 d0 3e 14 11 4a f2 dc 45 8a e0 39 44 de 51 26 fe 08 d6 6a 6e f3 ba this data is encrypted with the server handshake traffic key auth tag 2e d1 02 5f 98 fe a6 d6 02 49 98 18 46 87 dc 06 this is the aead authentication tag that confirms the integrity of the encrypted data and the packet header it is produced by the encryption algorithm and consumed by the decryption algorithm decryption this data is encrypted using the server handshake traffic key and iv that were generated during the handshake keys calc step the iv will be modified by xor ing it by the packet number which in this case is 1 the process also takes as input the 20 bytes of header at the beginning of this packet as authenticated data that must match for decryption to succeed because the openssl command line tool does not yet support aead ciphers i ve written command line tools to both decrypt and encrypt this data from the handshake keys calc step key 17abbf0a788f96c6986964660414e7ec iv 09597a2ea3b04c00487e71f3 from this record recdata e00000000105635f63696405735f63696440cf01 authtag 2ed1025f98fea6d6024998184687dc06 recordnum 1 may need to add i and l flags for include and lib dirs cc o aes_128_gcm_decrypt aes_128_gcm_decrypt c lssl lcrypto cat tmp msg1 aes_128_gcm_decrypt iv recordnum key recdata authtag hexdump c 00000000 06 43 ff 40 b9 46 1e 8a 23 40 58 98 8e 7f 26 4d c f x m 00000010 7a b6 a5 1a 21 c6 29 79 b7 a6 79 f4 a0 87 70 85 z y y p snip crypto frame header 06 43 ff 40 b9 crypto frames create a single stream of bytes used by tls to establish a secure connection 06 frame type crypto 43 ff variable length integer first two bits indicate 2 byte integer showing crypto stream data offset of 0x3ff 1023 bytes 40 b9 variable length integer first two bits indicate 2 byte integer showing crypto stream data length of 0xb9 185 bytes certificateverify tls record fragment 46 1e 8a 23 40 58 98 8e 7f 26 4d 7a b6 a5 1a 21 c6 29 79 b7 a6 79 f4 a0 87 70 85 6e 92 6d 37 1b 2e 89 16 9a a1 90 b8 03 63 6b b1 0c 0f b9 05 98 3d 2b 50 0a ad 26 83 df be 15 6e cc f6 66 de 1a 5a d4 5d 77 38 d5 e7 8b d1 7b c3 e6 d2 5f 9a d4 af ba 8f 81 de 9f 4d 55 72 11 8e 08 55 1a 4b b9 4b 56 a9 70 e8 04 c6 82 67 45 4b 51 7f c8 38 6c 9b ae 3a 77 cc cb 7f 29 0f 6e 58 fb a1 26 f0 53 33 a1 1f 8a b0 89 2e 6e 7a 89 58 53 82 d3 6e ef 25 29 cf 5b 7b this crypto frame contains the remainder of this tls record it is represented in detail below handshake finished tls record 14 00 00 20 06 8f cb 60 6a a1 c8 aa 35 4d 7b 60 64 a3 32 8c f3 76 bc d9 f3 20 0e 68 ac e3 de 2e e9 fc ac cb this record is represented in detail below tls certificateverify the server provides information that ties the ephemeral public key generated during server key exchange generation to the ownership of the certificate s private key tls handshake header 0f 00 01 04 each tls handshake message starts with a type and a length 0f handshake message type 0x0f certificate verify 00 01 04 0x104 260 bytes of handshake message data follows signature algorithm 08 04 the server indicates the signature type 08 04 assigned value for rsa_pss_rsae_sha256 signature length 01 00 the server indicates that 0x100 256 bytes of signatu...
|