// import tls "github.com/refraction-networking/utls"
tcpConn, err := net.Dial("tcp", "tlsfingerprint.io:443")
if err != nil {
fmt.Printf("net.Dial() failed: %+v\n", err)
return
}
config := tls.Config{ServerName: "tlsfingerprint.io"}
// This fingerprint includes feature(s), not fully supported by TLS.
// uTLS client with this fingerprint will only be able to to talk to servers,
// that also do not support those features.
tlsConn := tls.Client(tcpConn, &tlsConfig, utls.HelloCustom)
clientHelloSpec := tls.ClientHelloSpec {
CipherSuites: []uint16{
tls.DISABLED_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384,
tls.DISABLED_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384,
tls.DISABLED_TLS_RSA_WITH_AES_256_CBC_SHA256,
0xc026,
0xc02a,
0x006b,
0x006a,
tls.TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA,
tls.TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA,
tls.TLS_RSA_WITH_AES_256_CBC_SHA,
0xc005,
0xc00f,
0x0039,
0x0038,
tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,
tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,
tls.TLS_RSA_WITH_AES_128_CBC_SHA256,
0xc025,
0xc029,
0x0067,
0x0040,
tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA,
tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,
tls.TLS_RSA_WITH_AES_128_CBC_SHA,
0xc004,
0xc00e,
0x0033,
0x0032,
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
tls.TLS_RSA_WITH_AES_256_GCM_SHA384,
0xc02e,
0xc032,
0x009f,
0x00a3,
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
tls.TLS_RSA_WITH_AES_128_GCM_SHA256,
0xc02d,
0xc031,
0x009e,
0x00a2,
0xc008,
tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA,
tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA,
0xc003,
0xc00d,
0x0016,
0x0013,
0x00ff,
0x00a7,
0x00a6,
0x006d,
0xc019,
0x003a,
0x006c,
0xc018,
0x0034,
0xc017,
0x001b,
tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA,
tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA,
tls.TLS_RSA_WITH_RC4_128_SHA,
0xc002,
0xc00c,
0x0004,
0xc016,
0x0018,
0x0009,
0x0015,
0x0012,
0x001a,
0x0008,
0x0014,
0x0011,
0x0019,
0x0003,
0x0017,
0x003b,
0xc006,
0xc010,
0x0002,
0xc001,
0xc00b,
0xc015,
0x0001,
0x001f,
0x0023,
0x0020,
0x0024,
0x001e,
0x0022,
0x0026,
0x0029,
0x0028,
0x002b,
tls.TLS_RSA_WITH_RC4_128_SHA,
0x0004,
},
CompressionMethods: []byte{
0x00, // compressionNone
},
Extensions: []tls.TLSExtension{
&tls.SupportedCurvesExtension{[]tls.CurveID{
tls.CurveP256,
tls.CurveP384,
tls.CurveP521,
}},
&tls.SupportedPointsExtension{SupportedPoints: []byte{
0x00, // pointFormatUncompressed
}},
&tls.SignatureAlgorithmsExtension{SupportedSignatureAlgorithms: []SignatureScheme{
tls.ECDSAWithP521AndSHA512,
tls.PKCS1WithSHA512,
tls.ECDSAWithP384AndSHA384,
tls.PKCS1WithSHA384,
tls.ECDSAWithP256AndSHA256,
tls.PKCS1WithSHA256,
0x0402,
0x0303,
0x0301,
0x0302,
tls.ECDSAWithSHA1,
tls.PKCS1WithSHA1,
0x0202,
},},
&tls.UtlsExtendedMasterSecretExtension{},
&tls.SNIExtension{},
},
}
tlsConn.ApplyPreset(clientHelloSpec)
n, err = tlsConn.Write("Hello, World!")
// or tlsConn.Handshake() for better control