From fe35c228accac562e79f6c96fc0f43d6cd63adcc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Mon, 13 Jul 2026 22:10:12 +0800 Subject: [PATCH 01/12] Update tls.md MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit jls-opts字段 --- docs/config/proxies/tls.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/docs/config/proxies/tls.md b/docs/config/proxies/tls.md index d8798ef9e..15cf97f52 100644 --- a/docs/config/proxies/tls.md +++ b/docs/config/proxies/tls.md @@ -22,6 +22,9 @@ proxies: enable: true config: base64_encoded_config # query-server-name: xxx.com + jls-opts: + username: jls-user + password: jls-password tlsmirror-opts: primary-key: MDEyMzQ1Njc4OWFiY2RlZjAxMjM0NTY3ODlhYmNkZWY= explicit-nonce-ciphersuites: [ @@ -132,6 +135,10 @@ reality 服务端私钥对应的公钥 支持 X25519-MLKEM768 密钥交换 +## jls-opts + +使用 sni 作为 JLS SNI + ## ech-opts ### ech-opts.enable From b1e07114f4d932da332ff6b55a8cad21f7e81dfd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Mon, 13 Jul 2026 22:14:03 +0800 Subject: [PATCH 02/12] Update tls.en.md --- docs/config/proxies/tls.en.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/docs/config/proxies/tls.en.md b/docs/config/proxies/tls.en.md index cc5753954..cff1e2b36 100644 --- a/docs/config/proxies/tls.en.md +++ b/docs/config/proxies/tls.en.md @@ -22,6 +22,9 @@ proxies: enable: true config: base64_encoded_config # query-server-name: xxx.com + jls-opts: + username: jls-user + password: jls-password tlsmirror-opts: primary-key: MDEyMzQ1Njc4OWFiY2RlZjAxMjM0NTY3ODlhYmNkZWY= explicit-nonce-ciphersuites: [ @@ -150,6 +153,10 @@ The ECH configuration, if empty, will be resolved via DNS; otherwise, it will be Optional, if not empty, it is used to specify the domain name when resolving via DNS. +## jls-opts + +Requires `tls: true`. Uses `servername` as the JLS SNI. + ## tlsmirror-opts When `tls` is `true`, configuring `tlsmirror-opts` enables tlsmirror. The TLS carrier used by tlsmirror uses `servername`, `alpn`, `skip-cert-verify`, `fingerprint`, `certificate`, `private-key`, `client-fingerprint`, and `ech-opts` from the same outbound. If `servername` is empty, `server` is used. From 16d616e789012859f023d96cd70b79fb69e821e3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Mon, 13 Jul 2026 22:15:01 +0800 Subject: [PATCH 03/12] Update tls.md --- docs/config/proxies/tls.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/config/proxies/tls.md b/docs/config/proxies/tls.md index 15cf97f52..c65ebe7b2 100644 --- a/docs/config/proxies/tls.md +++ b/docs/config/proxies/tls.md @@ -135,10 +135,6 @@ reality 服务端私钥对应的公钥 支持 X25519-MLKEM768 密钥交换 -## jls-opts - -使用 sni 作为 JLS SNI - ## ech-opts ### ech-opts.enable @@ -156,6 +152,10 @@ ECH 配置,如果为空则通过 dns 解析,不为空则通过该值指定 可选项,不为空时用于指定通过 dns 解析时的域名 +## jls-opts + +使用 sni 作为 JLS SNI + ## tlsmirror-opts 当 `tls` 为 `true` 且配置 `tlsmirror-opts` 时启用 tlsmirror。tlsmirror 的 TLS 载体会使用同一出站中的 `servername`、`alpn`、`skip-cert-verify`、`fingerprint`、`certificate`、`private-key`、`client-fingerprint` 和 `ech-opts` 配置;`servername` 为空时使用 `server`。 From 9317fb560dd6376e9369a6223e503a27bd7b25c9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Mon, 13 Jul 2026 22:17:02 +0800 Subject: [PATCH 04/12] Update tls.ru.md --- docs/config/proxies/tls.ru.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/docs/config/proxies/tls.ru.md b/docs/config/proxies/tls.ru.md index b525bdc15..b0c7ef79a 100644 --- a/docs/config/proxies/tls.ru.md +++ b/docs/config/proxies/tls.ru.md @@ -22,6 +22,9 @@ proxies: enable: true config: base64_encoded_config # query-server-name: xxx.com + jls-opts: + username: jls-user + password: jls-password tlsmirror-opts: primary-key: MDEyMzQ1Njc4OWFiY2RlZjAxMjM0NTY3ODlhYmNkZWY= explicit-nonce-ciphersuites: [ @@ -151,6 +154,10 @@ openssl x509 -noout -fingerprint -sha256 -inform pem -in yourcert.pem Этот параметр необязателен; если он не пуст, он используется для указания доменного имени при разрешении через DNS. +## jls-opts + +Требуется `tls: true`. Использует `servername` в качестве JLS SNI. + ## tlsmirror-opts Когда `tls` установлен в `true`, наличие `tlsmirror-opts` включает tlsmirror. TLS carrier, используемый tlsmirror, берет `servername`, `alpn`, `skip-cert-verify`, `fingerprint`, `certificate`, `private-key`, `client-fingerprint` и `ech-opts` из того же outbound. Если `servername` пустой, используется `server`. From ff0084e7ca1568a180a564c2ed9de7a9165cffe9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Mon, 13 Jul 2026 22:36:19 +0800 Subject: [PATCH 05/12] Update tls.en.md --- docs/config/proxies/tls.en.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/config/proxies/tls.en.md b/docs/config/proxies/tls.en.md index cff1e2b36..7020b157d 100644 --- a/docs/config/proxies/tls.en.md +++ b/docs/config/proxies/tls.en.md @@ -155,7 +155,7 @@ Optional, if not empty, it is used to specify the domain name when resolving via ## jls-opts -Requires `tls: true`. Uses `servername` as the JLS SNI. +Uses `sni` as the JLS SNI. ## tlsmirror-opts From 2c5d72643b4957ec91a748ad4754acd868d737de Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Mon, 13 Jul 2026 22:38:28 +0800 Subject: [PATCH 06/12] Update tls.ru.md --- docs/config/proxies/tls.ru.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/config/proxies/tls.ru.md b/docs/config/proxies/tls.ru.md index b0c7ef79a..bc6324875 100644 --- a/docs/config/proxies/tls.ru.md +++ b/docs/config/proxies/tls.ru.md @@ -156,7 +156,7 @@ openssl x509 -noout -fingerprint -sha256 -inform pem -in yourcert.pem ## jls-opts -Требуется `tls: true`. Использует `servername` в качестве JLS SNI. +Использует `sni` в качестве JLS SNI. ## tlsmirror-opts From 0553cbd371453541ebc4c15165369c9864c546af Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Tue, 14 Jul 2026 10:06:26 +0800 Subject: [PATCH 07/12] Update tls.en.md --- docs/config/proxies/tls.en.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/config/proxies/tls.en.md b/docs/config/proxies/tls.en.md index 7020b157d..59b5163b5 100644 --- a/docs/config/proxies/tls.en.md +++ b/docs/config/proxies/tls.en.md @@ -155,7 +155,7 @@ Optional, if not empty, it is used to specify the domain name when resolving via ## jls-opts -Uses `sni` as the JLS SNI. +Requires `tls: true`. Uses `sni` / `servername` from the general configuration as the JLS SNI. ## tlsmirror-opts From 049776b828f1b55337d5c2d41c567a671e7fcab6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Tue, 14 Jul 2026 10:07:48 +0800 Subject: [PATCH 08/12] Update tls.md --- docs/config/proxies/tls.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/config/proxies/tls.md b/docs/config/proxies/tls.md index c65ebe7b2..74dceeb1b 100644 --- a/docs/config/proxies/tls.md +++ b/docs/config/proxies/tls.md @@ -154,7 +154,7 @@ ECH 配置,如果为空则通过 dns 解析,不为空则通过该值指定 ## jls-opts -使用 sni 作为 JLS SNI +需要开启 `tls: true`。使用通用配置中的 `sni` / `servername` 作为 JLS 的 SNI。 ## tlsmirror-opts From d8eb0b77807f24088944f6e3b1dce157b4cbcfc1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Tue, 14 Jul 2026 10:08:54 +0800 Subject: [PATCH 09/12] Update tls.ru.md --- docs/config/proxies/tls.ru.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/config/proxies/tls.ru.md b/docs/config/proxies/tls.ru.md index bc6324875..a15d99765 100644 --- a/docs/config/proxies/tls.ru.md +++ b/docs/config/proxies/tls.ru.md @@ -156,7 +156,7 @@ openssl x509 -noout -fingerprint -sha256 -inform pem -in yourcert.pem ## jls-opts -Использует `sni` в качестве JLS SNI. +Требуется включить `tls: true`. Использует `sni` / `servername` из общих настроек в качестве JLS SNI. ## tlsmirror-opts From c32e01a572a2ef36dd35417f1aac193fa4540738 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Wed, 15 Jul 2026 18:23:16 +0800 Subject: [PATCH 10/12] Update tls.en.md --- docs/config/proxies/tls.en.md | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/docs/config/proxies/tls.en.md b/docs/config/proxies/tls.en.md index 59b5163b5..287ebbfd4 100644 --- a/docs/config/proxies/tls.en.md +++ b/docs/config/proxies/tls.en.md @@ -22,9 +22,12 @@ proxies: enable: true config: base64_encoded_config # query-server-name: xxx.com + shadow-tls-opts: + version: 3 + password: shadow-tls-password jls-opts: - username: jls-user - password: jls-password + username: jls-user + password: jls-password tlsmirror-opts: primary-key: MDEyMzQ1Njc4OWFiY2RlZjAxMjM0NTY3ODlhYmNkZWY= explicit-nonce-ciphersuites: [ @@ -153,6 +156,14 @@ The ECH configuration, if empty, will be resolved via DNS; otherwise, it will be Optional, if not empty, it is used to specify the domain name when resolving via DNS. +## shadow-tls-opts + +Requires `tls: true`. Uses `sni` / `servername` from the general configuration as the ShadowTLS SNI. + +### shadow-tls-opts.version + +Supports `v1` / `v2` / `v3`. Defaults to `v2` if left empty. + ## jls-opts Requires `tls: true`. Uses `sni` / `servername` from the general configuration as the JLS SNI. From 1e2936026d231bddf1e46f719043702f9f3e546c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Wed, 15 Jul 2026 18:25:18 +0800 Subject: [PATCH 11/12] Update tls.md --- docs/config/proxies/tls.md | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) diff --git a/docs/config/proxies/tls.md b/docs/config/proxies/tls.md index 74dceeb1b..ef98026ff 100644 --- a/docs/config/proxies/tls.md +++ b/docs/config/proxies/tls.md @@ -22,9 +22,12 @@ proxies: enable: true config: base64_encoded_config # query-server-name: xxx.com - jls-opts: - username: jls-user - password: jls-password + shadow-tls-opts: + version: 3 + password: shadow-tls-password + jls-opts: + username: jls-user + password: jls-password tlsmirror-opts: primary-key: MDEyMzQ1Njc4OWFiY2RlZjAxMjM0NTY3ODlhYmNkZWY= explicit-nonce-ciphersuites: [ @@ -152,6 +155,14 @@ ECH 配置,如果为空则通过 dns 解析,不为空则通过该值指定 可选项,不为空时用于指定通过 dns 解析时的域名 +## shadow-tls-opts + +需要开启 `tls: true`;使用通用配置中的 `sni` / `servername` 作为 ShadowTLS 的 SNI。 + +### shadow-tls-opts.version + +支持 `v1` / `v2` / `v3`;留空时默认为 `v2`。 + ## jls-opts 需要开启 `tls: true`。使用通用配置中的 `sni` / `servername` 作为 JLS 的 SNI。 From d52bc15009afb2a82bc6ccdb5f5f0281b015c388 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=B9=85=E6=8B=BE=E5=BF=86?= Date: Wed, 15 Jul 2026 18:27:29 +0800 Subject: [PATCH 12/12] Update tls.ru.md --- docs/config/proxies/tls.ru.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/docs/config/proxies/tls.ru.md b/docs/config/proxies/tls.ru.md index a15d99765..49fbc9dde 100644 --- a/docs/config/proxies/tls.ru.md +++ b/docs/config/proxies/tls.ru.md @@ -22,6 +22,9 @@ proxies: enable: true config: base64_encoded_config # query-server-name: xxx.com + shadow-tls-opts: + version: 3 + password: shadow-tls-password jls-opts: username: jls-user password: jls-password @@ -154,6 +157,14 @@ openssl x509 -noout -fingerprint -sha256 -inform pem -in yourcert.pem Этот параметр необязателен; если он не пуст, он используется для указания доменного имени при разрешении через DNS. +## shadow-tls-opts + +Требуется включить `tls: true`. Использует `sni` / `servername` из общих настроек в качестве ShadowTLS SNI. + +### shadow-tls-opts.version + +Поддерживаются версии `v1` / `v2` / `v3`. По умолчанию используется `v2`, если поле оставлено пустым. + ## jls-opts Требуется включить `tls: true`. Использует `sni` / `servername` из общих настроек в качестве JLS SNI.