Skip to content

About

On-device DNSSEC validation for Dart over an injected DNS-over-HTTPS transport, failing closed on unsigned or invalid answers.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

 
 

Repository files navigation

dnssec_resolver

On-device DNSSEC validation over an injected DohWireTransport; unsigned and invalid answers fail closed.

DnssecResolver performs validation locally and clears any resolver-provided AD bit before evaluating an answer. Callers control the DNS-over-HTTPS transport, including whether it connects directly or through SOCKS. The transport remains owned by the caller and must be closed when it is no longer needed; see example/dnssec_resolver_example.dart.

Root trust anchors

The released Hickory dependency contains the IANA KSK-2017 and KSK-2024 root anchors. KSK-2024 is required for the root signing-key rollover scheduled for October 11, 2026. IANA schedules KSK-2017 for revocation on January 11, 2027 and removal on March 22, 2027. The native test suite deliberately fails at the revocation date until the pinned trust-anchor set is reviewed and updated.

About

On-device DNSSEC validation for Dart over an injected DNS-over-HTTPS transport, failing closed on unsigned or invalid answers.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors

Languages