As an administrator, I want support for DNS over TLS (DoT) or DNS over HTTPS (DoH) in FreeIPA so that all DNS traffic within modern deployments can be authenticated, authorized, and encrypted, ensuring secure communication in a Zero-Trust environment.
In modern deployments, the internal network can no longer be trusted, which means that all traffic must be authenticated, authorized, and encrypted. Encrypted DNS ensures secure communication by enforcing the use of DoT/DoH protocols, encrypting all DNS queries and responses. This feature aims to integrate encrypted DNS seamlessly into the FreeIPA management framework, allowing administrators to decide whether the DNS traffic must be encrypted or not.
Currently, FreeIPA does not support DoT/DoH, and DNS traffic within the internal network is not encrypted.
FreeIPA should support DoT/DoH, allowing administrators to configure and enforce encrypted DNS traffic. This would ensure that all DNS queries and responses are securely encrypted, adhering to Zero-Trust principles.
Metadata Update from @frenaud: - Custom field rhbz adjusted to https://issues.redhat.com/browse/RHEL-67912, https://issues.redhat.com/browse/RHEL-67913
master:
ipa-4-12:
Metadata Update from @frenaud: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)