summaryrefslogtreecommitdiffstats
path: root/contrib/dnspriv
diff options
context:
space:
mode:
authorDaniel Baumann <daniel.baumann@progress-linux.org>2024-05-05 18:37:14 +0000
committerDaniel Baumann <daniel.baumann@progress-linux.org>2024-05-05 18:37:14 +0000
commitea648e70a989cca190cd7403fe892fd2dcc290b4 (patch)
treee2b6b1c647da68b0d4d66082835e256eb30970e8 /contrib/dnspriv
parentInitial commit. (diff)
downloadbind9-upstream.tar.xz
bind9-upstream.zip
Adding upstream version 1:9.11.5.P4+dfsg.upstream/1%9.11.5.P4+dfsgupstream
Signed-off-by: Daniel Baumann <daniel.baumann@progress-linux.org>
Diffstat (limited to 'contrib/dnspriv')
-rw-r--r--contrib/dnspriv/README.md23
-rw-r--r--contrib/dnspriv/named.conf18
-rw-r--r--contrib/dnspriv/nginx.conf41
3 files changed, 82 insertions, 0 deletions
diff --git a/contrib/dnspriv/README.md b/contrib/dnspriv/README.md
new file mode 100644
index 0000000..8fa6795
--- /dev/null
+++ b/contrib/dnspriv/README.md
@@ -0,0 +1,23 @@
+<!--
+ - Copyright (C) Internet Systems Consortium, Inc. ("ISC")
+ -
+ - This Source Code Form is subject to the terms of the Mozilla Public
+ - License, v. 2.0. If a copy of the MPL was not distributed with this
+ - file, You can obtain one at http://mozilla.org/MPL/2.0/.
+ -
+ - See the COPYRIGHT file distributed with this work for additional
+ - information regarding copyright ownership.
+-->
+### DNS Privacy in BIND
+
+This directory contains sample configuration files to enable BIND,
+with Nginx as a TLS proxy, to provide DNS over TLS.
+
+`named.conf` configures a validating recursive name server to listen
+on the localhost address at port 8853.
+
+`nginx.conf` configures a TLS proxy to listen on port 853 and
+forward queries and responses to `named`.
+
+For more information, please see
+[https://dnsprivacy.org/wiki/](https://dnsprivacy.org/wiki/)
diff --git a/contrib/dnspriv/named.conf b/contrib/dnspriv/named.conf
new file mode 100644
index 0000000..12d07a3
--- /dev/null
+++ b/contrib/dnspriv/named.conf
@@ -0,0 +1,18 @@
+/*
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
+ *
+ * This Source Code Form is subject to the terms of the Mozilla Public
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
+ * file, You can obtain one at http://mozilla.org/MPL/2.0/.
+ *
+ * See the COPYRIGHT file distributed with this work for additional
+ * information regarding copyright ownership.
+ */
+
+options {
+ listen-on port 8853 { 127.0.0.1; };
+ allow-query { localhost; };
+ recursion yes;
+ dnssec-validation auto;
+ tcp-clients 1024;
+};
diff --git a/contrib/dnspriv/nginx.conf b/contrib/dnspriv/nginx.conf
new file mode 100644
index 0000000..65e3868
--- /dev/null
+++ b/contrib/dnspriv/nginx.conf
@@ -0,0 +1,41 @@
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
+#
+# This Source Code Form is subject to the terms of the Mozilla Public
+# License, v. 2.0. If a copy of the MPL was not distributed with this
+# file, You can obtain one at http://mozilla.org/MPL/2.0/.
+#
+# See the COPYRIGHT file distributed with this work for additional
+# information regarding copyright ownership.
+
+# uncomment to choose an appropriate UID/GID; default is 'nobody'
+# user bind bind;
+
+worker_processes auto;
+pid /var/run/nginx.pid;
+
+events {
+ worker_connections 1024;
+ multi_accept on;
+}
+
+stream {
+ upstream dns_tcp_servers {
+ server 127.0.0.1:8853;
+ }
+
+ server {
+ listen 853 ssl;
+ proxy_pass dns_tcp_servers;
+
+ # update to a suitable SSL certificate (e.g. from LetsEncrypt),
+ # and uncomment the following lines:
+ # ssl_certificate /etc/nginx/lego/certificates/<cert>.crt;
+ # ssl_certificate_key /etc/nginx/lego/certificates/<cert>.key;
+
+ ssl_protocols TLSv1.2;
+ ssl_ciphers ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
+ ssl_session_tickets on;
+ ssl_session_timeout 4h;
+ ssl_handshake_timeout 30s;
+ }
+}