# How to Enable Transport-Layer Encryption in OpenFlux

> Secure your OpenFlux connections with transport-layer encryption. Learn how to enable AES-256-GCM encryption using shared secrets and command-line flags for enhanced security.

- Repository: [p1neappleXpress/OpenFlux](https://github.com/p1neappleXpress/OpenFlux)
- Tags: how-to-guide
- Published: 2026-09-13

---

**OpenFlux enables transport-layer encryption between clients and exit nodes by wrapping any underlying transport in an AES-256-GCM encrypted layer using a shared secret file and command-line flags.**

The OpenFlux networking tool provides built-in transport-layer security that sits transparently between your application traffic and the underlying network socket. When you enable transport-layer encryption in OpenFlux, all packets exchanged between the client and exit node receive authenticated encryption protection, preventing eavesdropping and tampering regardless of whether you use raw sockets, Windivert, or other transport implementations.

## Prerequisites: Creating a Shared Secret

Before establishing encrypted tunnels, both peers must possess identical secrets of at least **16 bytes**. The library located in [`transport/encrypted.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/transport/encrypted.go) uses this secret to derive directional encryption keys via scrypt.

Generate a secure shared secret and save it to a file:

```bash

# Create a secret with at least 16 characters

echo "my-very-strong-shared-secret-1234" > mysecret.key

```

This file must be accessible to both the client and exit node at runtime.

## Step-by-Step Configuration

### Configure the Exit Node

The exit node requires the `-exit-node` flag alongside the encryption key file to activate the encrypted transport wrapper. According to the source in [`main/main.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/main/main.go) (lines 95-100), the binary instantiates an `EncryptedTransport` around the inner transport when these flags are present.

Launch the exit node with raw socket privileges:

```bash
sudo ./openflux -exit-node \
    -encryption-key-file=mysecret.key \
    -transport=rawsocket \
    -listen=:9000

```

The `-exit-node` boolean flag tells `NewEncryptedTransport` to use the exit-to-client directional key for outbound traffic.

### Configure the Client

Clients connect through the encrypted tunnel by specifying the same secret file and transport type. The client automatically derives the complementary directional key for client-to-exit communication.

Start the client with SOCKS5 forwarding enabled:

```bash
./openflux -encryption-key-file=mysecret.key \
    -transport=rawsocket \
    -socks-addr=127.0.0.1:1080 \
    -exit-node=false

```

OpenFlux will log `Transport encryption: AES-256-GCM enabled` upon successful initialization, indicating that the scrypt key derivation and GCM cipher setup completed successfully.

## How the Encryption Layer Works

The implementation in [`transport/encrypted.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/transport/encrypted.go) handles all cryptographic operations automatically once the shared secret is provided.

### Key Derivation with Scrypt

When `NewEncryptedTransport` initializes, it calls `deriveDirectionalKey` to generate separate keys for each traffic direction:

1. **Context extraction** – The code derives a salt from the transport type (e.g., `tcp`) or the `globalDocUrl` if configured, which overrides the default context
2. **Scrypt execution** – Uses the shared secret and context to produce cryptographically secure keys via the scrypt KDF
3. **Directional separation** – Creates distinct keys for client-to-exit and exit-to-client streams, preventing cross-direction leakage

### AEAD Stream Protection

Each directional stream uses **AES-256-GCM** authenticated encryption:

- The `newGCM` function initializes the cipher with the derived directional keys
- All packets include authentication tags to prevent tampering
- The encryption wraps the underlying `Transport` interface defined in [`transport/transport.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/transport/transport.go), making it compatible with raw sockets, Windivert, or other transports

### Replay Protection

The `EncryptedTransport` maintains a bounded map (`seen`/`seenOrder`) tracking recent nonces. This mechanism rejects duplicate packets, preventing replay attacks against the tunnel.

### Optional Compression Layer

OpenFlux applies compression after encryption. The [`transport/compressor.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/transport/compressor.go) file implements an optional compression layer that sits atop the encrypted transport defined in [`transport/encrypted.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/transport/encrypted.go), ensuring that compression operates on plaintext while encryption protects the compressed payload.

## Summary

- **Transport-layer encryption** in OpenFlux uses AES-256-GCM with scrypt key derivation as implemented in [`transport/encrypted.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/transport/encrypted.go)
- Both peers require a shared secret file of at least 16 bytes passed via `-encryption-key-file`
- The `-exit-node` flag determines directional key usage, with separate keys preventing cross-traffic leakage
- Replay protection is built-in through nonce tracking in a bounded map (`seen`/`seenOrder`)
- Encryption can be applied to any underlying transport implementing the `Transport` interface

## Frequently Asked Questions

### What encryption algorithm does OpenFlux use for transport-layer security?

OpenFlux uses **AES-256-GCM** (Galois/Counter Mode) authenticated encryption. The implementation in [`transport/encrypted.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/transport/encrypted.go) creates GCM ciphers via the `newGCM` function, providing both confidentiality and integrity protection for all packets exchanged between peers.

### How long does the shared secret need to be?

The shared secret must be **at least 16 bytes** in length. While the code accepts longer secrets, 16 bytes represents the minimum threshold for the scrypt-based key derivation function used to generate the directional AES keys.

### Can I enable transport-layer encryption with any transport type?

Yes. The `EncryptedTransport` struct wraps any implementation of the `Transport` interface defined in [`transport/transport.go`](https://github.com/p1neappleXpress/OpenFlux/blob/main/transport/transport.go). This includes `rawsocket`, Windivert, or custom transports, allowing you to layer AES-256-GCM encryption over TCP, UDP, or other protocols without modifying the encryption logic.

### Does enabling encryption affect OpenFlux performance?

Encryption adds computational overhead through scrypt key derivation and AES-256-GCM operations. However, the implementation uses efficient nonce tracking and AEAD block operations that typically introduce minimal latency for most use cases. The security benefits of preventing traffic analysis and tampering generally outweigh the modest performance cost.