Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upIntegration of DNSSEC #2344
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
andrewdavidwong
Sep 30, 2016
Member
Which Qubes component(s) are you proposing that DNSSEC be implemented in?
|
Which Qubes component(s) are you proposing that DNSSEC be implemented in? |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
rugk
Sep 30, 2016
The local DNS resolver if there is already one...
Basically the aim is that all applications use a local DNS server (You know, never trust something outside of the device) and that this DNS resolver uses DNSSEC to verify the DNS responses.
As said this is best combined with #2341.
rugk
commented
Sep 30, 2016
|
The local DNS resolver if there is already one... Basically the aim is that all applications use a local DNS server (You know, never trust something outside of the device) and that this DNS resolver uses DNSSEC to verify the DNS responses. As said this is best combined with #2341. |
andrewdavidwong
added
enhancement
C: other
help wanted
labels
Oct 1, 2016
andrewdavidwong
added this to the Far in the future milestone
Oct 1, 2016
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Oct 1, 2016
Member
https://wiki.debian.org/DNSSEC
On Debian DNSSEC can be made to work by installing dnssec-trigger. But I don't know what it actually does. If it uses the user's ISP DNS server and just enables DNSSEC or uses some alternative DNS server.
|
https://wiki.debian.org/DNSSEC On Debian DNSSEC can be made to work by installing |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
rugk
commented
Oct 2, 2016
|
I think the dns server should/is not be changed automatically. |
rugk commentedSep 29, 2016
A DNSSEC verification by default would be a nice thing to have.
Also some DNSCrypt servers (see #2341) offer DNSSEC. Of course, however, if you trust the DNSCrypt server enough, you do not have to verify DNSSEC, but yeah I know... Qubes OS trust's nobody.😄