[dnsdist] DoH and DoT on the same IP:port via different SNIs? (was: dnsdist 1.4.0-beta1 released)

Christoph cm at appliedprivacy.net
Fri Jun 7 19:56:00 UTC 2019


Remi Gacogne wrote:
> This version [...] adds a new rule to route queries based on the
> incoming TLS Server Name Indication (SNI) value. 

Is this the first step towards supporting DoH and DoT on a single
IP:port and dnsdist will tell them apart via SNI?

dot.example.com:443

doh.example.com:443

(both would resolve to the same IP)




More information about the dnsdist mailing list