From bd93da0d4722c24fb82121eafae32506168a60b2 Mon Sep 17 00:00:00 2001
From: Daniel Micay By default, in the automatic mode, the Private DNS feature provides opportunistic
encryption by using DNS-over-TLS when supported by the DNS server IP addresses
- provided by the network or the static IP configuration. Opportunistic encryption
- provides protection against a passive listener, not an active attacker, since they can
- force falling back to unencrypted DNS by blocking DNS-over-TLS. In the automatic mode,
- certificate validation is not enforced, as it would provide no additional security and
- would reduce the availability of opportunistic encryption.
When Private DNS is explicitly enabled, it uses authenticated encryption without a fallback. The authentication is performed based on the hostname of the server, so it