[TLS] Possible blocking of Encrypted SNI extension in China
onoketa <onoketa@iyouport.org> Thu, 30 July 2020 15:46 UTC
Hi, The Great Firewall of China may have identified and blocked Cloudflare's ESNI implementation. I have found that when using a TLS client hello with ESNI extension to connect to servers behind Cloudflare's CDN, the connection will be cut off after the whole TLS handshake is done. And then that IP address will be blocked at the TCP level for several minutes. onoketa
