Logging with Unencrypted DNS, DoT and DoH

2024-09-17 Thread Bischof, Ralph F. (MSFC-IS64)[AEGIS] via bind-users
Hello, BIND 9.18.7 RHEL 8.10 (Oopta) I am being asked if it is possible to differentiate the percentage of queries coming into a server that are unencrypted, DoT and DoH. Example: For a given 24 hours, 50% were 53, 25% were 853 and 25% were 443. I cannot find a difference in the query logs to sh

RE: Logging with Unencrypted DNS, DoT and DoH

2024-09-17 Thread Richard T.A. Neal
Hi Ralph, I don't believe this is presently possible but it's being considered for future development. Please see the following Issue Ticket for more details: https://gitlab.isc.org/isc-projects/bind9/-/issues/2748 Best, Richard. From: bind-users On Behalf Of Bischof, Ralph F. (MSFC-IS64)[A

RE: Logging with Unencrypted DNS, DoT and DoH

2024-09-17 Thread John W. Blue via bind-users
Ralph, You already may be aware of the BIND webinar's put on by ISC and presented by Carsten: https://www.isc.org/docs/BIND_9webinar2.pdf https://www.youtube.com/watch?v=7Uu6XvY68SM If not, spend some time watching the video and would like to point out that slide 12 lists several COTS vendors