How does the client learn the encrypted and unencrypted DNS servers are operated by the same administrative domain ?
The client can authenticate the encrypted DNS servers but cannot authenticate the unencrypted DNS server !
If it is genuinely impossible to prove association between two resolvers when one resolver is unencrypted, then perhaps we should not have the concept at all. But I'm hoping it is not impossible.
How does the client learn the encrypted and unencrypted DNS servers are operated by the same administrative domain ?
The client can authenticate the encrypted DNS servers but cannot authenticate the unencrypted DNS server !
Originally posted by @tireddy2 in #2 (comment)
The text was updated successfully, but these errors were encountered: