
TokenPLS:向 Mihomo 提交 OpenVPN tls-auth 摘要算法修复
TokenPLS 在排查 tls-crypt 超时时发现 tls-auth 固定 HMAC-SHA1 会导致 auth SHA256/SHA512 握手失败,并向 Mihomo 提交 PR #3189;强调这是独立问题,不代表 tls-crypt 原故障已解决。该 PR 后已合并。
作者原文@TokenPLSUpdate on the tls-crypt investigation.
We now have an interop test that runs the OpenVPN outbound against an official OpenVPN 2.7.5 server with
tls-crypt,tls-crypt-v2,tls-authandauth-user-pass. We will post its results here once the run completes.One finding already: the upstream
tls-authimplementation hard-codes HMAC-SHA1, so any profile that combinestls-authwithauth SHA256orauth SHA512cannot complete the handshake at all. That is a different bug from yours; we sent the fix upstream in https://github.com/MetaCubeX/mihomo/pull/3189. If you try thetls-authcomparison we asked for, expect it to fail for that reason until the fix ships, so that comparison is not informative for now.tls-cryptdoes not depend onauth, so your profile is not affected by that bug.Still the most useful data for your case: the server-side
openvpn --verb 4lines from the moment the app tries to connect (or confirmation that the server logs nothing at all), and whether the official client on the same Mac connects with the same profile.