What
Expose additional TLS, DNS, and network signals to HAProxy policy and Berghain challenges.
Current state
SPOE validation receives a limited request identity, and the shipped policy does not consume TLS fingerprints, DNSBL, or FCrDNS results.
Sketch
- Add optional JA3N/JA4, DNSBL, forward/reverse DNS, and FCrDNS inputs.
- Pass only the signals required by the selected challenge or HAProxy policy.
What
Expose additional TLS, DNS, and network signals to HAProxy policy and Berghain challenges.
Current state
SPOE validation receives a limited request identity, and the shipped policy does not consume TLS fingerprints, DNSBL, or FCrDNS results.
Sketch