Skip to content

dnsdist: Is there a way to start DoT for specific domain name (wild-card certificate)? #13828

Answered by rgacogne
ousatov-ua asked this question in Q&A
Discussion options

You must be logged in to vote

No, it's not possible to only listen for specific domains as we listen on an IP address and port. It is possible to filter queries during the rule processing on the TLS name requested by the client, see SNIRule: https://dnsdist.org/reference/selectors.html#SNIRule

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by ousatov-ua
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
2 participants