4 ms·
> since verified DDR needs a TLS cert covering the resolver's IP it's effectively public-resolver-only Why would you think this? It's trivial to get certs for
by wolrah 2mo ago
> since verified DDR needs a TLS cert covering the resolver's IP it's effectively public-resolver-only
Why would you think this? It's trivial to get certs for internal services that mainstream devices trust, they just have to use names from a portion of the public DNS space that you can demonstrate control over. It doesn't actually have to be publicly exposed.