I am the network admin here. Please follow my rules.
At least now I know to check.
I am the network admin here. Please follow my rules.
At least now I know to check.
When DNS over HTTPS (DoH) was announced many of its proponents seem to dismiss, or at least downplay, this concern often.
They should be using a client-side-TLS-signed (and verified) DoT only at their own DNS-forward-blocking border gateway with their wireguarded remote DNS resolver unless multiple DNS views are so desired (such as QubeOS desktops) then it is down the rabbit hole for DNS experts only.
(I frequently forget to say this often but always configure for one at the start.)
Corporate Bonus if you can scrub all TLS traffic at kernel level while running a transparent HTTPS/TLS proxy at the border gateway: that is, force all TLS through that proxy by payload detection mechanism and not just by port numbers.
>> May 06 16:34:03 host.contoso.com dockerd[1496]: time="2023-05-06T16:34:03.666703897Z" level=info msg="No non-localhost DNS nameservers are left in resolv.conf. Using default external servers: [nameserver 8.8.8.8 nameserver 8.8.4.4]"
>> May 06 16:34:03 host.contoso.com dockerd[1496]: time="2023-05-06T16:34:03.666734656Z" level=info msg="IPv6 enabled; Adding default IPv6 external servers: [nameserver 2001:4860:4860::8888 nameserver 2001:4860:4860::8844]"
I'm running Unbound on these machines.
systemd-resolved still isn't helping much for me at this either.
Go to the biggest flowchart of resolv.conf in this detailed writeup.
In an organisation - sure. But sometimes countries act like a giant man-in-the-middle redirecting/blocking forbidden sites e.g. Russia. Most popular DNS servers like 1.1.1.1 and 8.8.8.8 are forced to comply.
(Looking at you, Great Firewall.)
Least you can get the DNS resolver working.
And the more that is blocked, the more traffic will move to port 443, maybe using some relays at big cloud providers.
I'd say, the job a network admin is to provide positive services: reliable transport of bits, reliable DNS resolvers, etc. Beyond that, a network admin should not look at what users are doing with those bits.
Split DNS is the easiest way to achieve this, but it breaks.
DoH is not the problem. I'm using it too. It is the "surprise" that my devices are not using the one given to them.
I'll be sure to tell that to the regulator overseeing my industry and my Compliance department.
So either the host must be trusted to conform to policy. In which case it up to the host admin to avoid bad setups, or the host should have no (direct) access to the internet.