unbound/dnscrypt
Wouter Wijngaards 52e2331dd4 - [dnscrypt] prevent dnscrypt-secret-key, dnscrypt-provider-cert
duplicates
- [dnscrypt] introduce dnscrypt-provider-cert-rotated option,
  from Manu Bretelle.
	This option allows handling multiple cert/key pairs while only
	distributing some of them.
	In order to reliably match a client magic with a given key without
	strong assumption as to how those were generated, we need both key and
	cert. Likewise, in order to know which ES version should be used.
	On the other hand, when rotating a cert, it can be desirable to only
	serve the new cert but still be able to handle clients that are still
	using the old certs's public key.
	The `dnscrypt-provider-cert-rotated` allow to instruct unbound to not
	publish the cert as part of the DNS's provider_name's TXT answer.



git-svn-id: file:///svn/unbound/trunk@4373 be551aaa-1e26-0410-a405-d3ace91eadb9
2017-10-17 07:34:49 +00:00
..
testdata - new keys and certs for dnscrypt tests. 2017-08-29 08:48:19 +00:00
cert.h - Fix #1276: [dnscrypt] add XChaCha20-Poly1305 cipher. 2017-06-06 12:52:26 +00:00
dnscrypt.c - [dnscrypt] prevent dnscrypt-secret-key, dnscrypt-provider-cert 2017-10-17 07:34:49 +00:00
dnscrypt.h - [dnscrypt] prevent dnscrypt-secret-key, dnscrypt-provider-cert 2017-10-17 07:34:49 +00:00
dnscrypt.m4 - Detect chacha for dnscrypt at configure time. 2017-06-08 08:17:38 +00:00
dnscrypt_config.h.in - #1217. DNSCrypt support, with --enable-dnscrypt, libsodium and then 2017-03-20 14:55:31 +00:00