Skip to content

Key double-checking for ODoH #2261

Open
@jedisct1

Description

https://www.ietf.org/archive/id/draft-schwartz-ohai-consistency-doublecheck-03.html suggests connecting twice to the relay in order to retrieve the keys: once to get the (possibly) cached content, and using the relay as a TCP proxy to connect to the upstream server.

This forces ODoH relays to also support acting as TCP relays. Something that makes me feel a little bit anxious. And an ODoH relay that would like to send different keys to different targets can pretend not to support TCP relaying.

Still something we may want to implement, and make optional.

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions