3 ms·
I posted on the signal community forums in significantly more detail (e.g. how to configure nginx exactly with test connections), but it's relatively easy to us
by maxmorlocke 8y ago
I posted on the signal community forums in significantly more detail (e.g. how to configure nginx exactly with test connections), but it's relatively easy to use AWS infrastructure only for pass through and configure nginx to accept specific public SNI headers while connecting to domains you are authoritative for (e.g. google.com, amazon.com, yahoo.com, yandex.ru). You can do this by using the ssl_preread nginx module to proxy based on the SNI header (e.g. amazon.com -> 127.0.0.1:444, google.com -> 127.0.0.1:445, yahoo.com -> 127.0.0.1:446). This effectively means that you are not having AWS or GAE do anything other than directly proxy encrypted content, which I would argue is an important distinction.
The downside is that no one is providing the DNS redirect in an encrypted transaction.