Skip to content

Get green in Project dnsprivacy-monitoring #15

@ryru

Description

@ryru

Our secure DNS resolvers are automatically tested to various DNS related tests by the dnsprivacy-monitoring project. Some tests although fail. More research and even configuration changes are required for:

  1. TLS 443: "Does the server answer DNS queries over TLS on port 443 with no SNI sent?"
  2. Strict Name 443: "Does the server pass Strict authentication using the authentication domain name only on 443 (some operators require an SNI on 443 to defend against attacks)?"
  3. Keepalive => The edns-tcp-keepalive EDNS0 Option RFC7828
  4. Padding => The EDNS(0) Padding Option [7830](https://datatracker.ietf.org/doc/rfc7830
  5. OOOR: "Does the server give Out Of Order Responses (Experimental, may give false negatives)?"

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions