Skip to content

ShadowsocksR — sing-box ​

sing-box has no ShadowsocksR implementation. The shadowsocksr type is recognized so existing configs parse, but any shadowsocksr outbound (or inbound) fails at startup with an error. The option schema below serves only as a reference when migrating such configs.

Outbound ​

type: "shadowsocksr":

FieldTypeDefaultAllowed valuesDescription
methodstring(required)aes-256-cfb | aes-128-ctr | chacha20-ietf | rc4-md5 | <other SSR ciphers>SSR cipher. The accepted set is the historical SSR cipher catalog — RC4, AES-CFB, AES-CTR, ChaCha20, etc. Modern AEAD ciphers belong on the regular Shadowsocks outbound.
passwordstring(required)<string>Server password.
obfsstring(unset)plain | http_simple | http_post | random_head | tls1.2_ticket_authObfuscation plugin. plain is no obfs; http_simple and http_post emit a fake HTTP request; tls1.2_ticket_auth mimics a TLS resumption.
obfs_paramstring(unset)<string>Plugin-specific parameter. For HTTP obfs, this is the Host header.
protocolstringoriginorigin | auth_aes128_md5 | auth_aes128_sha1 | auth_sha1_v4 | auth_chain_a | auth_chain_bProtocol-layer plugin. origin is no plugin; the auth_* family adds per-packet authentication.
protocol_paramstring(unset)<string>Protocol-layer parameter. Many plugins use this as a user-count or rate-limit hint.
networkNetworkList(tcp+udp)tcp | udp | Restrict to TCP-only or UDP-only.

Source: option/shadowsocksr.go:3-13 · pinned at v1.14.2 (af6e64c)

Embeds DialerOptions and ServerOptions.

Examples ​

Plain SSR with HTTP-obfs:

json
{
  "outbounds": [
    {
      "type": "shadowsocksr",
      "tag": "ssr-out",
      "server": "example.com",
      "server_port": 443,
      "method": "aes-256-cfb",
      "password": "<password>",
      "obfs": "http_simple",
      "obfs_param": "www.bing.com",
      "protocol": "auth_chain_a",
      "protocol_param": "32"
    }
  ]
}

TLS-ticket-auth obfs:

json
{
  "outbounds": [
    {
      "type": "shadowsocksr",
      "server": "example.com",
      "server_port": 443,
      "method": "chacha20-ietf",
      "password": "<password>",
      "obfs": "tls1.2_ticket_auth",
      "obfs_param": "www.bing.com",
      "protocol": "auth_chain_b"
    }
  ]
}

Notes ​

  • The shadowsocksr outbound is a stub: its options are parsed, but creating it always fails (include/registry.go:170-179). Use a mihomo ssr proxy instead, or move the server to Shadowsocks or another modern protocol.
  • The accepted method, obfs, and protocol strings are the historical SSR catalog. The "modern" Shadowsocks ciphers (AEAD, 2022-blake3-*) belong on the Shadowsocks outbound instead.
  • The auth_chain_* protocol plugins are the only ones still in active use today — the older auth_aes128_* and auth_sha1_v4 variants are vulnerable to a replay-attack class identified in 2018.

Cross-core notes ​

  • Xray-core does not support SSR. See SSR — Xray-core.
  • mihomo uses cipher (not method) and kebab-case for the parameter fields (obfs-param, protocol-param). See SSR — mihomo.

Source: option/shadowsocksr.go:3-13 · v1.14.2 (af6e64c)

Core Tutorial by Argsment