dnsdist: Is there a way to start DoT for specific domain name (wild-card certificate)? #13828
-
Hi all!
Is there a way to do it? Thank you in advance! |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
No, it's not possible to only listen for specific domains as we listen on an IP address and port. It is possible to filter queries during the rule processing on the TLS name requested by the client, see |
Beta Was this translation helpful? Give feedback.
-
@rgacogne Thank you! |
Beta Was this translation helpful? Give feedback.
No, it's not possible to only listen for specific domains as we listen on an IP address and port. It is possible to filter queries during the rule processing on the TLS name requested by the client, see
SNIRule
: https://dnsdist.org/reference/selectors.html#SNIRule