NuSkooler wrote (2020-06-22):
I can't remember the status of this and didn't see it skimming the info pack - is there a official port/setup/etc. for bink over TLS for fsxNet?
The unofficial status for TLS in fsxnet: half broken / interoperability issues 1/100, 2/100 and 4/100 are still using deprecated TLS crypto.
This is my setup:
- port 24553
- TLS 1.2 and 1.3 only
- SNI disabled for all outgoing connections
- self-signed cert
- TOFU for outgoing connections (trust on first use)
My server also refuses TLS 1.3 connections that transmits the domain name via SNI in clear text (experimental). As binkp doesn't use domain-based virtual hosting and the nodelist supports custom ports, SNI is just a useless metadata leak in binkps connections.
---
* Origin: (21:3/102)