About
Background
ECH encrypts the TLS Client Hello with a public key the client fetches from DNS ahead of time, so an on-path observer can no longer read which hostname (i.e., SNI) a connection is for.
This site is a web front end for echtool, a tool for measuring how servers deploy ECH. It connects to a single domain, offers an ECH configuration, and reports how the server answered. These commands are available here:
- greasy: offers a GREASE configuration, a well-formed but fake one the server cannot decrypt. A server that supports ECH rejects it and hands back its real configurations as retry configurations. echtool can replay the handshake with them to confirm they work, and compares them with the configuration the domain publishes in its DNS HTTPS record.
- conn: connects with a real ECH configuration you supply, e.g. one from DNS or from an earlier greasy run. Individual fields (config ID, version, public name, cipher suites, …) can be overridden to see how the server handles variations.
- dech: decodes a base64 ECH configuration into its fields. No connection is made.
The test command runs experiments against one or more domains at once. Its modes are only
available in the CLI:
- test grace-period CLI only: measures how long a server keeps accepting a retry configuration after rotation. It re-offers the configuration at a fixed interval until the server stops accepting it, while tracking the DNS HTTPS record and the retry configurations the server hands out, and repeats this over several cycles to check the lifetimes are consistent. Since it waits for the server to rotate its configuration, a run may need to go on for a long time.
- test configuration-variations CLI only: varies one field of an ECH configuration at a time and reports which variations the server accepts.
A probe against a domain (over TCP or QUIC) is classified as one of:
| Status | Meaning |
|---|---|
| accepted | the server completed the handshake using the offered configuration |
| rejected | the server understood ECH but rejected the offered configuration, optionally returning fresh retry configurations |
| not accepted | the handshake completed, but without ECH |
| failed | the connection failed or never started, so the target said nothing about ECH either way |
Project team
Jonas Mücke, TU Dresden
Contact
For questions about ECH handshakes, this tool, or anything it reports, reach out at jonas.muecke@tu-dresden.de.