Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

allow Do53 for local zones? #29

Open
mcmanus opened this issue Aug 29, 2019 · 1 comment
Open

allow Do53 for local zones? #29

mcmanus opened this issue Aug 29, 2019 · 1 comment

Comments

@mcmanus
Copy link
Collaborator

mcmanus commented Aug 29, 2019

I hesitate to suggest this, but it might be a compromise that would really help deployment.

The idea would be a dnszone found on a locally designated (i.e. via RA) server could opt-in to being looked up over plaintext 53. probably opt-in via an attribute in dohNS and be signed.

The idea being that a legacy setup could transition to internet doh while not having to setup a new server for intranet stuff thus making it easier to swallow. Definitely a trade-off, but maybe a winner. discuss!

@tfpauly
Copy link
Owner

tfpauly commented Aug 29, 2019

Yes, I think that does make sense. It should be up to the client, potentially, about limiting what can be done for this, but anything that's going to the local resolver anyhow is already somewhat less private.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants