[dns-operations] 答复: A dns-proxy for DNS over HTTP(s)

Paul Wouters paul at nohats.ca
Sun May 17 17:26:33 UTC 2015


On Sun, 17 May 2015, Davey Song (宋林健) wrote:

> Thank you for your feedback.
>
> I will look into the feature of unbound, you mean unbound also support
> HTTP(s)?

Yes, you can reach it on public servers at:

Fedora servers:
140.211.169.201
66.35.62.163
152.19.134.150
2610:28:3090:3001:dead:beef:cafe:fed9

It is used by dnssec-trigger in a last-ditch attempt if the dhcp
supplied server is dnssec-broken and port 53 is not free or
redirected to the broken server. It instructs unbound to use these
servers over TLS on port 443 for raw TCP DNS. The only downside is
it is not keeping a persistent TCP (or TLS) connection, so it is
terribly slow and leads to timeouts.

> It's my mistake, please try  http://24.104.150.213

I'm confused as that is not using TLS?

Paul



More information about the dns-operations mailing list