AdguardTeam / AdguardTeam/AdGuardHome
[Feature Request] An option to always return `NXDOMAIN` for TYPE65 (HTTPS) query
- Ngôn ngữ chính
- TypeScript
- Star
- 36.9k
- Fork
- 2.5k
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
### Prerequisites
- [x] I have checked the [Wiki](https://github.com/AdguardTeam/AdGuardHome/wiki) and [Discussions](https://github.com/AdguardTeam/AdGuardHome/discussions) and found no answer
- [x] I have searched other issues and found no duplicates
- [x] I want to request a feature or enhancement and not ask a question
### The problem
Enterprise network needs IDS/IPS to meet the PCI-DSS (and many other security) requirements. This includes sniffing plain client hello to get the domain name from the HTTPS connection. ECH (Encrypted Client Hello) breaks that.
Per https://developers.cloudflare.com/ssl/edge-certificates/ech/, it is possible to disable ECH in browsers like Chrome by simply returning `NXDOMAIN` to TYPE65 (`HTTPS`) DNS query.
### Proposed solution
Add an option to AdGuardHome to return all `NXDOMAIN` to TYPE65 (`HTTPS`) DNS query.
### Alternatives considered and additional information
Haven't tested this out yet, but this rule might work, I don't know:
```
||*^$dnstype=HTTPS|TYPE65,dnsrewrite=NXDOMAIN
```
Hướng dẫn đóng góp
Đánh giá
Issue này chưa được đánh giá.