public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* request for info: unbound via https / tls
@ 2018-04-04 17:38 Paul Simmons
  2018-04-05  9:43 ` Michael Tremer
  0 siblings, 1 reply; 4+ messages in thread
From: Paul Simmons @ 2018-04-04 17:38 UTC (permalink / raw)
  To: development

[-- Attachment #1: Type: text/plain, Size: 530 bytes --]

For Core119, I'm currently using a patch to /etc/init.d/unbound:

 https://gitlab.com/snippets/1706804

because my (only available) ISP mangles port 53 traffic, effectively
disabling DNS outside of my private firewall.

I wonder if configuring unbound so that forward requests use DNSSEC
over HTTPS or TLS would be a better (and more secure) solution? Also
see:

https://forum.ipfire.org/viewtopic.php?f=27&t=20575#p115342

https://forum.ipfire.org/viewtopic.php?f=50&t=20574

Comments and test configurations are welcome!

Paul


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2018-04-05 14:31 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-04-04 17:38 request for info: unbound via https / tls Paul Simmons
2018-04-05  9:43 ` Michael Tremer
2018-04-05 13:28   ` Paul Simmons
2018-04-05 14:31     ` Michael Tremer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox