3 ms·
TL;DR This is a way for admins to enforce network policies without needing to see the decrypted traffic. You can use this to enforce domain blocklists for DNS o
by doomrobo 4y ago
TL;DR This is a way for admins to enforce network policies without needing to see the decrypted traffic. You can use this to enforce domain blocklists for DNS over HTTPS: client proves their requested domain is not banned (a few sec) and middlebox verifies (a few millisec)