[dnsdist] DoH and DoT on the same IP:port via different SNIs? (was: dnsdist 1.4.0-beta1 released)
remi.gacogne at powerdns.com
Tue Jun 11 13:14:47 UTC 2019
On 6/7/19 9:56 PM, Christoph wrote:
>> This version [...] adds a new rule to route queries based on the
>> incoming TLS Server Name Indication (SNI) value.
> Is this the first step towards supporting DoH and DoT on a single
> IP:port and dnsdist will tell them apart via SNI?
> (both would resolve to the same IP)
It's a very nice idea, but I'm afraid it's unlikely to happen due to the
fact that we use libh2o to handle incoming connections on DoH ports and
not on DoT ones, so it would be hard to mix them.
PowerDNS.COM BV - https://www.powerdns.com/
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 488 bytes
Desc: OpenPGP digital signature
More information about the dnsdist