3 ms·
Depending on your local resolver, you possibly can provide DoH on localhost as well? I'm using unbound, and it was trivial to also provide DoH on localhost wit
by sillystuff 3y ago
Depending on your local resolver, you possibly can provide DoH on localhost as well? I'm using unbound, and it was trivial to also provide DoH on localhost with a funky port, so 443 localhost remains available for other things (my motivation was that firefox also doesn't support ESNI without a DoH resolver; I assume this is still true for ECH as well, but haven't re-visited).
For firefox, you can use a self-signed cert on your resolver (firefox did not work with ed25519, it did work with NIST P-256; I wanted a small key for lower overhead [having to use TLS + HTTP encapsulation for a resolver on localhost bothered me in irrational ways, and I was determined to minimize the overhead, even if the rational part of my brain said the overhead difference was too negligible to matter]). Add it with:
edit-> settings -> (search "cert" in 'find in settings') -> view certificates -> (server tab) -> add exception -> enter the url:
https://localhost:4353/dns-query https://localhost:4353/dns-query
ensure "permanent" is checked
The file, "cert_override.txt" is created by firefox after adding the cert exception, which can be copied to other profiles for provisioning.
The gui DoH config will create the following in about:config which can be used for provisioning with user.js:
network.trr.uri https://localhost:4353/dns-query
network.trr.bootstrapAddress 127.0.0.1
network.trr.mode 3
trr true
(network.trr.custom_uri is not used for anything but display in the gui)
network.trr.custom_uri https://localhost:4353/dns-query
I don't think chromium requires DoH for ESNI / HTTPSSVC, so it can just use plain-text localhost:53 as before. If it does need DoH for this, I do not know the equivalent to the above config, for chromium.