summaryrefslogtreecommitdiffstats
path: root/dnsdist-dnscrypt.cc
diff options
context:
space:
mode:
Diffstat (limited to 'dnsdist-dnscrypt.cc')
-rw-r--r--dnsdist-dnscrypt.cc49
1 files changed, 49 insertions, 0 deletions
diff --git a/dnsdist-dnscrypt.cc b/dnsdist-dnscrypt.cc
new file mode 100644
index 0000000..9930144
--- /dev/null
+++ b/dnsdist-dnscrypt.cc
@@ -0,0 +1,49 @@
+/*
+ * This file is part of PowerDNS or dnsdist.
+ * Copyright -- PowerDNS.COM B.V. and its contributors
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of version 2 of the GNU General Public License as
+ * published by the Free Software Foundation.
+ *
+ * In addition, for the avoidance of any doubt, permission is granted to
+ * link this program with OpenSSL and to (re)distribute the binaries
+ * produced as the result of such linking.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License
+ * along with this program; if not, write to the Free Software
+ * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
+ */
+#include "dolog.hh"
+#include "dnsdist.hh"
+#include "dnscrypt.hh"
+
+#ifdef HAVE_DNSCRYPT
+int handleDNSCryptQuery(PacketBuffer& packet, DNSCryptQuery& query, bool tcp, time_t now, PacketBuffer& response)
+{
+ query.parsePacket(packet, tcp, now);
+
+ if (query.isValid() == false) {
+ vinfolog("Dropping DNSCrypt invalid query");
+ return false;
+ }
+
+ if (query.isEncrypted() == false) {
+ query.getCertificateResponse(now, response);
+
+ return false;
+ }
+
+ if (packet.size() < static_cast<uint16_t>(sizeof(struct dnsheader))) {
+ ++g_stats.nonCompliantQueries;
+ return false;
+ }
+
+ return true;
+}
+#endif