Re: [opennic-discuss] DNS over HTTPS?

Rouben <[email protected]> Fri, 8 Nov 2019 08:00:03 -0500
Newsgroups gmane.network.opennic.general
Message-ID <CAGShw4=jyPE1-11z5ndOfRyH_Y_pVhZXwCKsmDh+iqRCFCFeyw@mail.gmail.com>
This is a multi-part message in MIME format...

------------=_1573218018-14772-3
Content-Type: multipart/alternative; boundary="000000000000ed60a00596d55c0c"

--000000000000ed60a00596d55c0c
Content-Type: text/plain; charset="UTF-8"

Thanks for sharing! Do you mind also sharing how you set that up? Which
implementations are you using?

On Fri, Nov 8, 2019 at 07:43 Timothy Rogers <[email protected]>
wrote:

> Morning,
>
> One of my instances VA1 already supports DoH and DoT, there are some
> issues with the DoT I am still trying to work out but the DoH I use on a
> daily basis. But due to requiring a valid SSL certificate, you have to use
> nsva1.hack13.me as the FQDN in Firefox or whatever device you are using
> it with.
>
> Timothy Francis Rogers
> [email protected]
> On Nov 8, 2019, 7:39 AM -0500, Rouben <[email protected]>, wrote:
>
> Would DoT (TLS) and DoH (HTTPS) require that we have our own CA
> established first? How is trust of DoH and DoT resolvers established?
>
> On Thu, Nov 7, 2019 at 19:12 Daniel Quintiliani <[email protected]> wrote:
>
>> (note: this is a repost of a message sent two weeks ago, according to
>> purrdeta, the mailing list was having problems at the time)
>>
>> Hi,
>>
>> Is there any possibility in the future for OpenNIC to offer a DNS over
>> HTTPS server as a replacement for CloudFlare in Firefox?
>>
>> Thank you,
>>
>> --
>>
>> -Dan Q
>>
>>
>> --------
>> You are a member of the OpenNIC Discuss list.
>> You may unsubscribe by emailing
>> [email protected]
>>
> --
> Rouben
>
>
> --------
> You are a member of the OpenNIC Discuss list.
> You may unsubscribe by emailing
> [email protected]
>
>
>
> --------
> You are a member of the OpenNIC Discuss list.
> You may unsubscribe by emailing
> [email protected]
>
-- 
Rouben

--000000000000ed60a00596d55c0c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div><div dir=3D"auto">Thanks for sharing! Do you mind also sharing how you=
 set that up? Which implementations are you using?</div></div><div><br><div=
 class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Nov 8,=
 2019 at 07:43 Timothy Rogers &lt;<a href=3D"mailto:opennic@timothyfrancisr=
ogers.me">[email protected]</a>&gt; wrote:<br></div><blockquo=
te class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc so=
lid;padding-left:1ex">



<div>
<div name=3D"messageBodySection">
<div dir=3D"auto">Morning,
<div dir=3D"auto"><br></div>
<div dir=3D"auto">One of my instances VA1 already supports DoH and DoT, the=
re are some issues with the DoT I am still trying to work out but the DoH I=
 use on a daily basis. But due to requiring a valid SSL certificate, you ha=
ve to use <a href=3D"http://nsva1.hack13.me" target=3D"_blank">nsva1.hack13=
.me</a> as the FQDN in Firefox or whatever device you are using it with.</d=
iv>
</div>
</div>
<div name=3D"messageSignatureSection"><br>
<div dir=3D"auto">Timothy Francis Rogers<br></div>
<div dir=3D"auto"><a href=3D"mailto:[email protected]" target=3D"_=
blank">[email protected]</a></div>
</div></div><div>
<div name=3D"messageReplySection">On Nov 8, 2019, 7:39 AM -0500, Rouben &lt=
;<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</=
a>&gt;, wrote:<br>
<blockquote type=3D"cite" style=3D"margin:5px 5px;padding-left:10px;border-=
left:thin solid #1abc9c">
<div>
<div>
<div dir=3D"auto">Would DoT (TLS) and DoH (HTTPS) require that we have our =
own CA established first? How is trust of DoH and DoT resolvers established=
?</div>
</div>
</div>
<div>
<div><br>
<div class=3D"gmail_quote">
<div dir=3D"ltr" class=3D"gmail_attr">On Thu, Nov 7, 2019 at 19:12 Daniel Q=
uintiliani &lt;<a href=3D"mailto:[email protected]" target=3D"_blank">danq@ru=
nbox.com</a>&gt; wrote:<br></div>
<blockquote class=3D"gmail_quote" style=3D"margin:5px 5px;padding-left:10px=
;border-left:thin solid #e67e22">(note: this is a repost of a message sent =
two weeks ago, according to purrdeta, the mailing list was having problems =
at the time)<br>
<br>
Hi,<br>
<br>
Is there any possibility in the future for OpenNIC to offer a DNS over HTTP=
S server as a replacement for CloudFlare in Firefox?<br>
<br>
Thank you,<br>
<br>
--<br>
<br>
-Dan Q<br>
<br>
<br>
--------<br>
You are a member of the OpenNIC Discuss list.<br>
You may unsubscribe by emailing <a href=3D"mailto:discuss-unsubscribe@lists=
.opennicproject.org" target=3D"_blank">[email protected]=
ject.org</a><br></blockquote>
</div>
</div>
</div>
--<br>
<div dir=3D"ltr" data-smartmail=3D"gmail_signature">Rouben</div>
<br>
<br>
--------<br>
You are a member of the OpenNIC Discuss list.<br>
You may unsubscribe by emailing <a href=3D"mailto:discuss-unsubscribe@lists=
.opennicproject.org" target=3D"_blank">[email protected]=
ject.org</a><br></blockquote>
</div>
</div>

<br>
<br>
--------<br>
You are a member of the OpenNIC Discuss list. <br>
You may unsubscribe by emailing <a href=3D"mailto:discuss-unsubscribe@lists=
.opennicproject.org" target=3D"_blank">[email protected]=
ject.org</a><br>
</blockquote></div></div>-- <br><div dir=3D"ltr" class=3D"gmail_signature" =
data-smartmail=3D"gmail_signature">Rouben</div>

--000000000000ed60a00596d55c0c--

------------=_1573218018-14772-3
Content-Type: text/plain; charset="UTF-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit



--------
You are a member of the OpenNIC Discuss list. 
You may unsubscribe by emailing [email protected]

------------=_1573218018-14772-3--