Skip to content

NaiveProxy ​

NaiveProxy carries traffic as HTTPS requests over HTTP/2, the way a browser talks to a web server. It needs TLS and a certificate, signs users in with a username and password, and is read by share links and sing-box apps.

What it is good for ​

  • Traffic shaped like a browser's. Its clients are built from a browser's own network code.
  • A TCP option with nothing else to tune: a port, a certificate, and the users.

It has no transport, so a CDN cannot carry it and an ingress cannot route to it. Give it its own port.

Create it ​

Inbounds → Add, type naive. The general form is on Inbounds.

  • Port on the Basic tab.
  • The TLS tab is required and starts on Node certificate. Read the certificate note below before you keep it.
  • Each user signs in with their account name and Password.
Field (Protocol tab)
Networktcp (default): HTTP/2 over TCP, which is what the share link describes. udp serves HTTP/3 over QUIC instead, and empty serves both. Keep tcp unless you know your users' apps handle HTTP/3
QUIC congestion control (advanced)bbr, cubic or reno, for HTTP/3. It travels in the link

Choose the certificate with care ​

A long-lived self-signed certificate is refused

The naive client in sing-box apps follows a browser's rule on certificate lifetime, even for a certificate it was told to trust. A self-signed certificate valid for longer than about 200 days fails with "cert validity too long", and that limit drops to 100 days in March 2027. The panel's own self-signed certificates, including the node certificate when it is self-signed, last a year.

Serve a naive inbound one of these instead:

  • An ACME certificate for a domain pointing at the node, issued on Certificates. It is trusted publicly, lasts 90 days with Let's Encrypt, and renews itself.
  • A certificate of your own with a validity under 100 days, pasted as a PEM pair.

Never served without users ​

A naive inbound with no users refuses to start, so the panel leaves it out of what a node is sent until at least one user is on it.

Client apps ​

Format
Share link (naive+https://)yes
sing-box appsyes
Clash appsno; their subscriptions leave it out
Xray-based appsno; their subscriptions leave it out

Text and images under CC BY 4.0.