-
Notifications
You must be signed in to change notification settings - Fork 10.4k
[1.1.1.1] Add Oblivious DNS over HTTPS #17906
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[1.1.1.1] Add Oblivious DNS over HTTPS #17906
Conversation
Deploying cloudflare-docs with
|
| Latest commit: |
e852008
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://3aeda13a.cloudflare-docs-7ou.pages.dev |
| Branch Preview URL: | https://rebecca-1-1-1-1-add-obliviou.cloudflare-docs-7ou.pages.dev |
src/content/docs/1.1.1.1/encryption/oblivious-dns-over-https.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/1.1.1.1/encryption/oblivious-dns-over-https.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/1.1.1.1/encryption/oblivious-dns-over-https.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/1.1.1.1/encryption/oblivious-dns-over-https.mdx
Outdated
Show resolved
Hide resolved
src/content/docs/1.1.1.1/encryption/oblivious-dns-over-https.mdx
Outdated
Show resolved
Hide resolved
xofyarg
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, thanks!
|
|
||
| Cloudflare 1.1.1.1 supports ODoH by acting as a target that can be reached at `odoh.cloudflare-dns.com`. | ||
|
|
||
| At launch, a few proxy partners included [PCCW](https://www.pccw.com/), [SURF](https://www.surf.nl/), and [Equinix](https://www.equinix.com/). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just for my own understanding: are they still included? "At launch" + "included" (past tense) made me a bit unsure if we're saying we still include them or not 😄
|
|
||
| Cloudflare 1.1.1.1 supports ODoH by acting as a target that can be reached at `odoh.cloudflare-dns.com`. | ||
|
|
||
| At launch, a few proxy partners included [PCCW](https://www.pccw.com/), [SURF](https://www.surf.nl/), and [Equinix](https://www.equinix.com/). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
needs rewording.
|
|
||
| Additionally, clients encrypt their query for the target using Hybrid Public Key Encryption (HPKE). A target's public key is obtained via DNS, where it is bundled into an HTTPS resource record and protected by DNSSEC. | ||
|
|
||
| ## Cloudflare and third-party products |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can we include Apple private relay?
* Create placeholder page, reorder, and adjust Encryption index * Initial outline and fill in intro * Fill in defined outline for a first complete version * Initial review: experimental status, remove OHTTP ref, and replace Rust client * Edit RFC callout, improve how it works section, and fix client link * Replace OHTTP blog with HPKE blog * Remove information already covered in the blog post * Add mention to iCloud Private Relay
Summary
PCX-7677
Documentation checklist