A DoT naming, publication, and discovery scheme

Brian Dickson (GoDaddy)


DNS over TLS Discovery

The DNS over TLS (DoT) protocol is well defined and ideal for client-to-recursive privacy. However, there is currently no way for a client to upgrade its connection to an existing resolver, for a number of reasons.

This talk concerns the impediments to doing an upgrade, and a proposal for a scheme that solves nearly all of them. The author has a PoC for the scheme, and will share the URI of that.


