Re: [tor-dev] DNS(SEC) draft update

2012-09-16 Thread Bry8 Star
If an Unbound type of DNSSEC/validating resolver exist on end-user's (tor proxy user's) computer, then, it can be configured to prevent accidental dns leaks from any apps on that computer, by using unbound configuration command-lines like: local-zone: "onion." refuse local-zone: "exit." refuse loca

Re: [tor-dev] DNS(SEC) draft update

2012-08-22 Thread Ondrej Mikle
On 08/20/2012 02:43 AM, Mike Perry wrote: > Thus spake Ondrej Mikle (ondrej.mi...@gmail.com): > >> I've revised the DNS draft, attaching it. In section 4 there are some options >> for integration with libunbound, but each of them requires some work with the >> stock libunbound code. > > I'm not a

Re: [tor-dev] DNS(SEC) draft update

2012-08-19 Thread Mike Perry
Thus spake Ondrej Mikle (ondrej.mi...@gmail.com): > I've revised the DNS draft, attaching it. In section 4 there are some options > for integration with libunbound, but each of them requires some work with the > stock libunbound code. I'm not a DNS expert, but I have a couple preliminary requests

[tor-dev] DNS(SEC) draft update

2012-08-19 Thread Ondrej Mikle
Hi Nick, I've revised the DNS draft, attaching it. In section 4 there are some options for integration with libunbound, but each of them requires some work with the stock libunbound code. Ondrej Filename: xxx-dns-dnssec.txt Title: Support for full DNS and DNSSEC resolution in Tor Authors: Ondrej