How to Enable Transport-Layer Encryption in OpenFlux
OpenFlux enables transport-layer encryption between clients and exit nodes by wrapping any underlying transport in an AES-256-GCM encrypted layer using a shared secret file and command-line flags.
The OpenFlux networking tool provides built-in transport-layer security that sits transparently between your application traffic and the underlying network socket. When you enable transport-layer encryption in OpenFlux, all packets exchanged between the client and exit node receive authenticated encryption protection, preventing eavesdropping and tampering regardless of whether you use raw sockets, Windivert, or other transport implementations.
Prerequisites: Creating a Shared Secret
Before establishing encrypted tunnels, both peers must possess identical secrets of at least 16 bytes. The library located in transport/encrypted.go uses this secret to derive directional encryption keys via scrypt.
Generate a secure shared secret and save it to a file:
# Create a secret with at least 16 characters
echo "my-very-strong-shared-secret-1234" > mysecret.key
This file must be accessible to both the client and exit node at runtime.
Step-by-Step Configuration
Configure the Exit Node
The exit node requires the -exit-node flag alongside the encryption key file to activate the encrypted transport wrapper. According to the source in main/main.go (lines 95-100), the binary instantiates an EncryptedTransport around the inner transport when these flags are present.
Launch the exit node with raw socket privileges:
sudo ./openflux -exit-node \
-encryption-key-file=mysecret.key \
-transport=rawsocket \
-listen=:9000
The -exit-node boolean flag tells NewEncryptedTransport to use the exit-to-client directional key for outbound traffic.
Configure the Client
Clients connect through the encrypted tunnel by specifying the same secret file and transport type. The client automatically derives the complementary directional key for client-to-exit communication.
Start the client with SOCKS5 forwarding enabled:
./openflux -encryption-key-file=mysecret.key \
-transport=rawsocket \
-socks-addr=127.0.0.1:1080 \
-exit-node=false
OpenFlux will log Transport encryption: AES-256-GCM enabled upon successful initialization, indicating that the scrypt key derivation and GCM cipher setup completed successfully.
How the Encryption Layer Works
The implementation in transport/encrypted.go handles all cryptographic operations automatically once the shared secret is provided.
Key Derivation with Scrypt
When NewEncryptedTransport initializes, it calls deriveDirectionalKey to generate separate keys for each traffic direction:
- Context extraction – The code derives a salt from the transport type (e.g.,
tcp) or theglobalDocUrlif configured, which overrides the default context - Scrypt execution – Uses the shared secret and context to produce cryptographically secure keys via the scrypt KDF
- Directional separation – Creates distinct keys for client-to-exit and exit-to-client streams, preventing cross-direction leakage
AEAD Stream Protection
Each directional stream uses AES-256-GCM authenticated encryption:
- The
newGCMfunction initializes the cipher with the derived directional keys - All packets include authentication tags to prevent tampering
- The encryption wraps the underlying
Transportinterface defined intransport/transport.go, making it compatible with raw sockets, Windivert, or other transports
Replay Protection
The EncryptedTransport maintains a bounded map (seen/seenOrder) tracking recent nonces. This mechanism rejects duplicate packets, preventing replay attacks against the tunnel.
Optional Compression Layer
OpenFlux applies compression after encryption. The transport/compressor.go file implements an optional compression layer that sits atop the encrypted transport defined in transport/encrypted.go, ensuring that compression operates on plaintext while encryption protects the compressed payload.
Summary
- Transport-layer encryption in OpenFlux uses AES-256-GCM with scrypt key derivation as implemented in
transport/encrypted.go - Both peers require a shared secret file of at least 16 bytes passed via
-encryption-key-file - The
-exit-nodeflag determines directional key usage, with separate keys preventing cross-traffic leakage - Replay protection is built-in through nonce tracking in a bounded map (
seen/seenOrder) - Encryption can be applied to any underlying transport implementing the
Transportinterface
Frequently Asked Questions
What encryption algorithm does OpenFlux use for transport-layer security?
OpenFlux uses AES-256-GCM (Galois/Counter Mode) authenticated encryption. The implementation in transport/encrypted.go creates GCM ciphers via the newGCM function, providing both confidentiality and integrity protection for all packets exchanged between peers.
How long does the shared secret need to be?
The shared secret must be at least 16 bytes in length. While the code accepts longer secrets, 16 bytes represents the minimum threshold for the scrypt-based key derivation function used to generate the directional AES keys.
Can I enable transport-layer encryption with any transport type?
Yes. The EncryptedTransport struct wraps any implementation of the Transport interface defined in transport/transport.go. This includes rawsocket, Windivert, or custom transports, allowing you to layer AES-256-GCM encryption over TCP, UDP, or other protocols without modifying the encryption logic.
Does enabling encryption affect OpenFlux performance?
Encryption adds computational overhead through scrypt key derivation and AES-256-GCM operations. However, the implementation uses efficient nonce tracking and AEAD block operations that typically introduce minimal latency for most use cases. The security benefits of preventing traffic analysis and tampering generally outweigh the modest performance cost.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →