On 5 Mar 2014, at 11:07, Francis Dupont <francis.dup...@fdupont.fr> wrote: > > I consider the first one to be already solved, cf. the Microsoft > deployed solution which puts clients, local networks, the resolver > (also the Microsoft Domain Server :-), in the same area and uses > IPsec to protect it.
I don't know if it is solved in a particularly satisfactory way. There is also DNScrypt supported by OpenDNS and DNS-over-TLS supported by Unbound. However neither of those do autoconfiguration, and I guess the Microsoft setup is not great for mobile devices. Tony. -- f.anthony.n.finch <d...@dotat.at> http://dotat.at/ _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop