-
Notifications
You must be signed in to change notification settings - Fork 14
Open
Description
DoHoT currently doesn't seem to mention and not doing local DNSSEC validation?
DoHoT seems to be based on dnscrypt-proxy which apparently doesn't do local DNSSEC validation. References:
- Feature Request: DNSSEC validating DNSCrypt/dnscrypt-proxy#1954
- DNSSEC Issues DNSCrypt/dnscrypt-proxy#167 (comment)
Also cloudflared apparently doesn't do local DNSSEC validation. References:
- validate DNSSEC cloudflare/cloudflared#520
- https://community.cloudflare.com/t/does-the-cloudflared-dns-client-locally-verify-dnssec/335402
Thank you for all your work on DNS security!
BTW I am interested in documenting and including it in our security distro:
https://www.kicksecure.com/wiki/DNS_Security
Metadata
Metadata
Assignees
Labels
No labels