You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I hesitate to suggest this, but it might be a compromise that would really help deployment.
The idea would be a dnszone found on a locally designated (i.e. via RA) server could opt-in to being looked up over plaintext 53. probably opt-in via an attribute in dohNS and be signed.
The idea being that a legacy setup could transition to internet doh while not having to setup a new server for intranet stuff thus making it easier to swallow. Definitely a trade-off, but maybe a winner. discuss!
The text was updated successfully, but these errors were encountered:
Yes, I think that does make sense. It should be up to the client, potentially, about limiting what can be done for this, but anything that's going to the local resolver anyhow is already somewhat less private.
I hesitate to suggest this, but it might be a compromise that would really help deployment.
The idea would be a dnszone found on a locally designated (i.e. via RA) server could opt-in to being looked up over plaintext 53. probably opt-in via an attribute in dohNS and be signed.
The idea being that a legacy setup could transition to internet doh while not having to setup a new server for intranet stuff thus making it easier to swallow. Definitely a trade-off, but maybe a winner. discuss!
The text was updated successfully, but these errors were encountered: