AdguardTeam / AdguardTeam/AdGuardHome
[Feature Request] An option to always return `NXDOMAIN` for TYPE65 (HTTPS) query
- Langage dominant
- TypeScript
- Étoiles
- 36.9k
- Forks
- 2.5k
- Métriques de merge des PR
- Aucune PR mergée en 30 j
Description
### Prerequisites
- [x] I have checked the [Wiki](https://github.com/AdguardTeam/AdGuardHome/wiki) and [Discussions](https://github.com/AdguardTeam/AdGuardHome/discussions) and found no answer
- [x] I have searched other issues and found no duplicates
- [x] I want to request a feature or enhancement and not ask a question
### The problem
Enterprise network needs IDS/IPS to meet the PCI-DSS (and many other security) requirements. This includes sniffing plain client hello to get the domain name from the HTTPS connection. ECH (Encrypted Client Hello) breaks that.
Per https://developers.cloudflare.com/ssl/edge-certificates/ech/, it is possible to disable ECH in browsers like Chrome by simply returning `NXDOMAIN` to TYPE65 (`HTTPS`) DNS query.
### Proposed solution
Add an option to AdGuardHome to return all `NXDOMAIN` to TYPE65 (`HTTPS`) DNS query.
### Alternatives considered and additional information
Haven't tested this out yet, but this rule might work, I don't know:
```
||*^$dnstype=HTTPS|TYPE65,dnsrewrite=NXDOMAIN
```
Guide de contribution
Ouvrir le guide de contribution
Évaluation
Cette issue n'a pas encore été évaluée.