tlswg / draft-ietf-tls-esni

TLS Encrypted Client Hello
https://tlswg.github.io/draft-ietf-tls-esni/#go.draft-ietf-tls-esni.html
Other
230 stars 56 forks source link

Question on Section 10.2 #517

Closed kylon94 closed 9 months ago

kylon94 commented 2 years ago

Section 10.2 of the draft suggests the use of DoH/DPRIVE when querying for the ECH record to protect against attacks on the local network. Should ECH be used for this DoH/DPRIVE query too?

Some guidance on whether or not to use it would be helpful for developers. For example covering how the ECH key should be provisioned if it is used.

chris-wood commented 9 months ago

Since this is specific to how ECH is bootstrapped, I suggest filing an issue to discuss this on the related DNS bootstrapping draft.