注意:

The Funtoo Linux project has transitioned to "Hobby Mode" and this wiki is now read-only.

Difference between revisions of "Package:Dnscrypt"

From Funtoo
Jump to navigation Jump to search
m
m (add some goodies)
Line 11: Line 11:


=== Configuration ===
=== Configuration ===
By default opendns is used, although some [http://www.opennicproject.org/ opennic servers] support dnscrypt.
{{f|/etc/conf.d/dnscrypt-proxy}} controls settings for DNScrypt.  A [https://github.com/jedisct1/dnscrypt-proxy/blob/master/dnscrypt-resolvers.csv list of resolvers] has been compiled for use with DNScrypt.
{{f|/etc/conf.d/dnscrypt-proxy}} controls settings for DNScrypt.  A [https://github.com/jedisct1/dnscrypt-proxy/blob/master/dnscrypt-resolvers.csv list of resolvers] has been compiled for use with DNScrypt.


Line 23: Line 25:
=== Testing ===
=== Testing ===
If you're using opendns, this welcome page will tell if your encrypted or not.
If you're using opendns, this welcome page will tell if your encrypted or not.
https://www.opendns.com/welcome/
;https://www.opendns.com/welcome/


If you're using any other encryption enabled dns servers, give them a leak test.  they should only report the dns servers associated with the one you chosen from the list.
;https://www.dnsleaktest.com/
{{EbuildFooter}}
{{EbuildFooter}}

Revision as of 18:29, February 21, 2015

Dnscrypt

   Tip

We welcome improvements to this page. To edit this page, Create a Funtoo account. Then log in and then click here to edit this page. See our editing guidelines to becoming a wiki-editing pro.

   Warning

As this page deals with DNS it has the potential to break your internet access! Ensure you have stable live media that can restore your system.

DNScrypt provides encryption from clients to upstream DNS servers. Encrypting this traffic prevents spying, spoofing, and other man in the middle attacks.

Installation

root # emerge dnscrypt-proxy

Configuration

By default opendns is used, although some opennic servers support dnscrypt.

/etc/conf.d/dnscrypt-proxy controls settings for DNScrypt. A list of resolvers has been compiled for use with DNScrypt.

   /etc/resolv.conf - set dns server as dnscrypt-proxy
nameserver 127.0.0.1

Service

root # rc-update add dnscrypt-proxy default
root # rc

Testing

If you're using opendns, this welcome page will tell if your encrypted or not.

https://www.opendns.com/welcome/

If you're using any other encryption enabled dns servers, give them a leak test. they should only report the dns servers associated with the one you chosen from the list.

https://www.dnsleaktest.com/