Dns over Tls (dot) / Dns over https (doh) with BIND9
Langsung setelah lama tidak mengikuti dns server bind versi baru mulai versi 9.17 sudah support doh dan dot, di sini memakai bind 9.18 di debian 11 tambahkan repo deb https://packages.sury.org/bind/ bullseye main pastikan gpg sudah di add dan install bind # apt install bind9 tambah di bind konfig nya /etc/bind/named.conf tls server-tls { cert-file "/etc/bind/ssl/cert.crt"; key-file "/etc/bind/ssl/privatekey.pem"; dhparam-file "/etc/bind/ssl/ssl-dhparams.pem"; protocols { TLSv1.2; TLSv1.3; }; ciphers "HIGH:!kRSA:!aNULL:!eNULL:!RC4:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS:!SHA1:!SHA256:!SHA384"; prefer-server-ciphers yes; session-tickets no; }; options { directory "/var/cache/bind"; dnssec-validation auto; listen-on port 853 tls server-tls { any; }; listen-on port 443 tls server-tls http default {any;}; forwarders { ...