2 ms·
ECH is encrypted using a public key obtained through DNS (specifically DNS-over-HTTPS[0]). My assumption is that you would terminate the ECH encryption at the e
by anderspitman 4y ago
ECH is encrypted using a public key obtained through DNS (specifically DNS-over-HTTPS[0]). My assumption is that you would terminate the ECH encryption at the edge, but everything else can be terminated with a separate cert at the origin server.
But I would be interested to know what deployment looks like in practice.
[0]: https://blog.cloudflare.com/encrypted-client-hello/ https://blog.cloudflare.com/encrypted-client-hello/