協議介紹
ALPN (Application Layer Protocol Negotiation)是TLS的擴展,允許在安全連接的基礎上進行應用層協議的協商。ALPN支持任意應用層協議的協商,目前應用最多是HTTP2的協商。在2016年,ALPN已經完全替代NPN了。
ALPN allows the application layer to negotiate which protocol to use over the secure connection. Any protocol can be negotiated by ALPN within a TLS connection. The protocols that are most commonly negotiated are HTTP/2 (for browsers that support it) and, historically, SPDY. The ALPN implementation is therefore not HTTP/2 or SPDY specific in any way.
協商原理
在TLS的Say Hello階段增加應用層協議的協商,如下圖所示:
通過協商獲取下一層協議,如下wireshark中顯示
客戶端的cient hello中:
服務端響應的Server hello中:
如果需要支持ALPN需要使用openssl1.0.2以上版本,
此協議擴展密鑰計算不影響。