[Pdns-users] Recursor forwarder DoT configuration

Christoph cm at appliedprivacy.net
Fri Sep 8 14:50:18 UTC 2023


Hello!

I'm looking for documentation about configuring
recursor to talk DoT to a recursive resolver.

This minimal config works:

dot-to-port-853=yes
forward-zones-recurse=.=1.1.1.1:853;1.0.0.1:853

but compared to DNSdist newServer() configuration options
I'm not sure about:

- does it validate the server certificate? how do I configure the name 
when performing certificate verification?
- does it support TCP fast open?
- does it support out of order processing?
- how are queries distributed across multiple servers?

Or is it generally better to have a
recursor -> dnsdist -> upstreams resolver
setup to be able to use dnsdist's configuration options there?

best regards,
Christoph


More information about the Pdns-users mailing list