DNS over HTTPS is not what I thought
petefreitag.com
petefreitag.com
# https://www.petefreitag.com/blog/dns-over-https/
function dnsq --description "Query DNS name(s) over HTTPs using JSON"
argparse --ignore-unknown 'h/help' 'd/dns=' 'n/name=+' 't/type=+' -- $argv
if set -q _flag_help
echo "Usage: $_ example.com"
echo ' -n --name DNS query name(s)'
echo ' -t --type DNS query type(s), ex: A (default), MX, TXT...'
echo ' -d --dns DNS query endpoint: cloudflare (default), google'
echo ' -h --help Print this help message and exit'
return 0
end
if not set -q _flag_name && test (count $argv) -eq 0
echo 'Missing name parameter.'
return 1
end
if not set -q _flag_type
set _flag_type 'A'
end
switch $_flag_dns
case 'google'
set url 'https://dns.google/resolve'
case 'cloudflare' '*'
set url 'https://cloudflare-dns.com/dns-query'
end
for type in $_flag_type
for name in $_flag_name $argv
set query (string join '&' (string join '=' 'name' $name) (string join '=' 'type' $type))
if isatty stdout && type -q jq
curl --header 'Accept: application/dns-json' --silent (string join '?' $url $query) | jq -r
else
curl --header 'Accept: application/dns-json' --silent (string join '?' $url $query)
end
end
end
end #!/bin/env bash
#--------------------------------------------
set -Eeuo pipefail
if [[ -n "${DEBUG:-}" ]]; then
set -x
fi
trap stack_trace ERR
function stack_trace() {
echo -e "\nThe command '$BASH_COMMAND' triggerd a stacktrace:\nStack Trace:"
for (( i = 1; i < ${#FUNCNAME[@]}; i++ )); do
echo " ($i) ${FUNCNAME[$i]:-(top level)} ${BASH_SOURCE[$i]:-(no file)}:${BASH_LINENO[$(( i - 1 ))]}"
done
}
error(){ echo "${1:-error message missing}" && trap true ERR && exit 1; }
SCRIPT_DIR="$(dirname "$(readlink -f "$0")")"
export SCRIPT_DIR
#--------------------------------------------
function dnsq {
# https://www.petefreitag.com/blog/dns-over-https/
while [[ $# -gt 0 ]]; do
case "$1" in
-h|--help)
echo "Usage: $0 example.com"
echo ' -n --name DNS query name(s)'
echo ' -t --type DNS query type(s), ex: A (default), MX, TXT...'
echo ' -d --dns DNS query endpoint: cloudflare (default), google'
echo ' -h --help Print this help message and exit'
return 0
;;
-n|--name)
shift
_flag_name+=("$1")
;;
-t|--type)
shift
_flag_type+=("$1")
;;
-d|--dns)
shift
_flag_dns="$1"
;;
\*)
_flag_name+=("$1")
;;
esac
shift
done
if [[ ${_flag_name:-} = "" ]]; then
echo 'Missing name parameter.'
return 1
fi
if [[ ${_flag_type:-} = "" ]]; then
_flag_type=("A")
fi
case ${_flag_dns:-cloudflare} in
"google")
url="https://8.8.8.8/resolve"
;;
"cloudflare")
url="https://1.1.1.1/dns-query"
;;
esac
for type in "${_flag_type[@]}"; do
for name in "${_flag_name[@]}"; do
query="name=$name&type=$type"
if [[ -t 1 ]] && command -v jq >/dev/null; then
curl --header 'Accept: application/dns-json' --silent "$url?$query" | jq -r
else
curl --header 'Accept: application/dns-json' --silent "$url?$query"
fi
done
done
}
dnsq "$@"Maybe in this case, because the author of the post only cares to check whether certain domains resolve or not, having the DNS server be resolved by normal DNS not DNS over HTTPS is fine, and that in other cases you’d hardcode an IP like with normal DNS resolution?
dns.google is 8.8.8.8 and cloudflare-dns.com is 1.1.1.1. You can replace the names with those IPs in the curl commands if you want, the certificates are valid for the IPs too.
As to how and when they're issued, section 3.2.2.5 of the Baseline Requirements explains how an Applicant can prove this is their IP address and so they're entitled to a certificate for that address. Note that the CA is entitled to choose which if any of the methods listed in 3.2.2.5 they will use, and it's not uncommon for the answer to be "None of them".
https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-...
That's not what the baseline says:
> The CA SHALL confirm that prior to issuance, the CA has validated each IP Address listed in the Certificate using at least one of the methods specified in this section.
You are confusing 3.2.2.5.4 with "no verification". It's done, just that the baseline trust that you are not an idiot and have some basis to confirm the ip address belongs to someone. And even that particular section has a sunset clause:
> CAs SHALL NOT perform validations using this method after July 31, 2019. Completed validations using this method SHALL NOT be re‐used for certificate issuance after July 31, 2019. Any certificate issued prior to August 1, 2019 containing an IP Address that was validated using any method that was permitted under the prior version of this Section 3.2.2.5 MAY continue to be used without revalidation until such certificate naturally expires.
I meant that it's not uncommon to just not issue such certificates, rather than you don't verify but you issue anyway, you don't verify because you always refuse to issue.
curl -H 'Accept: application/dns-json' 'https://dns.google/resolve?name=example.com&type=A'