Be more specific in resolved.conf man page with regard to DNSOverTLS
DNSOverTLS in strict mode (value yes) does check the server, as it is said in the first few lines of the option documentation. The check is not performed in "opportunistic" mode, however, as that is allowed by RFC 7858, section "4.1. Opportunistic Privacy Profile". > With such a discovered DNS server, the client might or might not validate the > resolver. These choices maximize availability and performance, but they leave > the client vulnerable to on-path attacks that remove privacy.
Loading
Please register or sign in to comment