Limits of TLS certificate validation in Consul DNS proxy for upstream DNS‑over‑TLS
24.8K reputation · 12 Feb 2025, 22:25 UTC
Limits of TLS certificate validation in Consul DNS proxy for upstream DNS‑over‑TLS
The Consul DNS proxy can forward queries to external DNS resolvers using DNS‑over‑TLS (DoT). Documentation states that the proxy does not perform TLS certificate validation on the upstream server; the client must handle verification. This leaves an unresolved decision about whether Consul can be configured to enforce chain validation for DoT upstreams, or if additional side‑car components are required.
Goal: determine if Consul’s DNS proxy can be made to validate the TLS certificates presented by DoT upstream servers without external tooling.
Questions:
- Is there a configuration option (e.g.,
ca_fileorverify_upstream) that enables TLS verification for the DNS proxy’s DoT connections? - If not, what are the recommended patterns for adding validation (e.g., using a local stub resolver or side‑car proxy)?
- Are there any planned changes to the DNS proxy behavior regarding upstream TLS validation in upcoming Consul releases?