public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* DNS over TLS performance and query randomisation across multiple forwarders
@ 2020-02-19 21:17 Peter Müller
  2020-02-20 14:37 ` Michael Tremer
  0 siblings, 1 reply; 2+ messages in thread
From: Peter Müller @ 2020-02-19 21:17 UTC (permalink / raw)
  To: development

[-- Attachment #1: Type: text/plain, Size: 803 bytes --]

Hello *,

while DNS over TLS is operational in upcoming Core Update 140/141, we
already discovered some performance issues due to missing TLS connection
reuse and similar optimisations.

Further, Unbound performs some measurements to determine response times
of given forwarders and submits all queries to the fastest one - which
obviously is a bad thing with a view to DNS privacy.

Stubby (https://dnsprivacy.org/wiki/display/DP/About+Stubby), which is
also written by NLnet Labs, aims to fix both issues.

Personally, I do not like the idea of putting another software before
Unbound in case the user decides to enable DNS over TLS. However, to discuss
this matter and further steps, mentioning it did sound reasonable to me. :-)

Thoughts/comments/opinions?

Thanks, and best regards,
Peter Müller

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2020-02-20 14:37 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-02-19 21:17 DNS over TLS performance and query randomisation across multiple forwarders Peter Müller
2020-02-20 14:37 ` Michael Tremer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox