Support for SSL/TLS ('wss://') on both sides.
On the client side, this adds the as3crypto library to web-socket-js
so that the WebSocket 'wss://' scheme is supported which is WebSocket
over SSL/TLS.
Couple of downsides to the fall-back method:
- This balloons the size of the web-socket-js object from about 12K to 172K.
- Getting it working required disabling RFC2718 web proxy support
in web-socket-js.
- It makes the web-socket-js fallback even slower with the
encryption overhead.
The server side (wsproxy.py) uses python SSL support. The proxy
automatically detects the type of incoming connection whether flash
policy request, SSL/TLS handshake ('wss://') or plain socket
('ws://').
Also added a check-box to the web page to enable/disabled 'wss://'
encryption.
This commit is contained in:
@@ -6,19 +6,24 @@ Description
|
||||
-----------
|
||||
|
||||
A VNC client implemented using HTML5, specifically Canvas and
|
||||
WebSocket.
|
||||
WebSocket (supports 'wss://' encryption).
|
||||
|
||||
For browsers that do not have builtin WebSocket support, the project
|
||||
includes web-socket-js, a WebSocket emulator using Adobe Flash
|
||||
(http://github.com/gimite/web-socket-js).
|
||||
|
||||
In addition, as3crypto has been added to web-socket-js to implement
|
||||
WebSocket SSL/TLS encryption, i.e. the "wss://" URI scheme.
|
||||
(http://github.com/lyokato/as3crypto_patched).
|
||||
|
||||
|
||||
Requirements
|
||||
------------
|
||||
|
||||
Until there is VNC server support for WebSocket connections, you need
|
||||
to use a WebSocket to TCP socket proxy. There is a python proxy
|
||||
included ('wsproxy').
|
||||
included ('wsproxy'). One advantage of using the proxy is that it has
|
||||
builtin support for SSL/TLS encryption (i.e. "wss://").
|
||||
|
||||
There a few reasons why a proxy is required:
|
||||
|
||||
@@ -38,6 +43,13 @@ There a few reasons why a proxy is required:
|
||||
the client asks the proxy (using the initial query string) to add
|
||||
sequence numbers to each packet.
|
||||
|
||||
To encrypt the traffic using the WebSocket 'wss://' URI scheme you
|
||||
need to generate a certificate for the proxy to load. You can generate
|
||||
a self-signed certificate using openssl. The common name should be the
|
||||
hostname of the server where the proxy will be running:
|
||||
|
||||
`openssl req -new -x509 -days 365 -nodes -out self.pem -keyout self.pem`
|
||||
|
||||
|
||||
Usage
|
||||
-----
|
||||
|
||||
Reference in New Issue
Block a user