Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.protocols.dns.bind > #15723

Re: DoH plugin for BIND

From Chuck Aurora <ca@nodns4.us>
Newsgroups comp.protocols.dns.bind
Subject Re: DoH plugin for BIND
Date 2020-05-05 11:20 -0500
Message-ID <mailman.353.1588695610.942.bind-users@lists.isc.org> (permalink)
References <20200502165717.E5F0F18A2F4E@ary.qy> <alpine.LNX.2.22.419.2005022019290.17860@desk.ddns.eckner.net> <d43c05c60b4a5284db47efa2c1247564@nodns4.us> <2c2c9ed1-b657-c14f-ea5f-b5d04f0eaf94@thelounge.net> <3c35c784bd56115b9b3e07ea33c35e35@nodns4.us>

Show all headers | View raw


On 2020-05-02 14:35, Reindl Harald wrote:
> Am 02.05.20 um 21:31 schrieb Chuck Aurora:
>> On 2020-05-02 13:23, Erich Eckner wrote:
>>> Will there be client-side DoT/DoH support in bind, too? E.g. will my
>>> recursive (or forwarding) resolver be able to resolve upstream dns 
>>> via
>> 
>> Well, a recursive resolver cannot use DoT/DoH for iterative queries to
>> authoritative NS servers, unless authoritative servers offered 
>> DoT/DoH,
>> and I don't think that's likely to happen.
>> 
>> Basically by deciding you want DoH/DoT upstream, you also have decided
>> that you want to use forwarders.
> 
> says who?
> 
> https://www.cira.ca/newsroom/canadian-shield/cira-launches-canadian-shield-provide-free-privacy-and-security-canadians

Thanks for the reply, but FWIW, I don't have a clue what point you
intended to make?  I looked at that CIRA page twice, and it is simply
a DoH/DoT forwarder.  Absolutely nothing in that release mentions any
change in DNS protocol.

DoH/DoT covers only one hop: the end user to the recursive resolver.
Beyond that one hop is good old-fashioned unencrypted DNS.  By using
DoH/DoT, whether in your own stub resolver or in a [future] BIND, you
are using that DoH/DoT server as your forwarder.

(Harald, please feel free to ignore Reply-To if you are unable to
post to the list.  Thanks.)

Back to comp.protocols.dns.bind | Previous | Next | Find similar | Unroll thread


Thread

Re: DoH plugin for BIND Chuck Aurora <ca@nodns4.us> - 2020-05-05 11:20 -0500

csiph-web