3 ms·
Is this what you had in mind? • https://wiki.archlinux.org/index.php/Dnscrypt-proxy#Local_DNS_cache_configuration https://wiki.archlinux.org/index.php/Dnscrypt
by dngray 7y ago
Is this what you had in mind?
• https://wiki.archlinux.org/index.php/Dnscrypt-proxy#Local_DNS_cache_configuration https://wiki.archlinux.org/index.php/Dnscrypt-proxy#Local_DN...
• https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a_Raspberry_Pi#Unbound_DNS_forwarder_with_dnscrypt https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a...
- 3xblah 7y agoNo. If it was, the tutorial would be focused on authoritative DNS providers, at least in part.
- 3xblah 7y agoI personally run CurveDNS but here is a quick and dirty script to show how DNSCrypt might be used to encrypt DNS traffic between stub resolvers or caches and authoritative servers, if authoritative DNS providers used dnscrypt-wrapper. To demonstrate we can pretend we are an authoritative DNS provider, e.g., a root server. See code, documentation and examples at https://github.com/Cofyc/dnscrypt-wrapper https://github.com/Cofyc/dnscrypt-wrapper # send end-to-end encypted DNS queries to/from an authoritative DNS server # send query for example.com to root server using stub resolver (drill) # authoritative DNS server (e.g., tinydns, nsd, etc.) listening on 127.0.0.1:53, serving root.zone from ftp.internic.net # dnscrypt-wrapper listening on 127.0.0.1:530 # dnscrypt-proxy listening on 127.0.0.1:5300 # could have dnscache or unbound forwarding to the dnscrypt-wrapper listening address dnscrypt-wrapper --gen-provider-keypair --provider-name=2.dnscrypt-cert.root.zone --ext-address=127.0.0.1:530 dnscrypt-wrapper --gen-crypt-keypair --crypt-secretkey-file=1.key dnscrypt-wrapper --gen-cert-file --crypt-secretkey-file=1.key --provider-cert-file=1.cert --provider-publickey-file=public.key --provider-secretkey-file=secret.key dnscrypt-wrapper -r 127.0.0.1:53 -a 127.0.0.1:530 --provider-name=2.dnscrypt-cert.root.zone --crypt-secretkey-file=1.key --provider-cert-file=1.cert -p 1.pid & k=$(dnscrypt-wrapper --show-provider-publickey|sed 's/Provider public key: //'); dnscrypt-proxy --provider-key=$k -a 127.0.0.1:5300 -r 127.0.0.1:530 --provider-name=2.dnscrypt-cert.root.zone -p 2.pid & drill example.com -p5300 @127.0.0.1 read a < 1.pid read b < 2.pid rm 1.key 1.cert public.key secret.key 1.pid 2.pid kill $a kill $b
- 3xblah 7y agos/queries/packets/