Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-67912

Support for DNS over TLS (DoT) in RHEL IdM

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Major Major
    • rhel-10.0
    • None
    • ipa
    • None
    • rhel-sst-idm-ipa
    • ssg_idm
    • 24
    • 26
    • 5
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • Automated
    • None

      Goal

      • As an administrator, I want support for DNS over TLS (DoT) in RHEL IdM so that all DNS traffic within modern deployments can be authenticated, authorized, and encrypted, ensuring secure communication in a Zero-Trust environment.

      Acceptance criteria

      A list of verification conditions, successful functional tests, or expected outcomes in order to declare this story/task successfully completed.

      • Verify administrators can enable and configure DNS over TLS (DoT) for DNS zones managed by RHEL IdM.
      • Verify encrypted DNS traffic (via DoT) is logged appropriately, with no sensitive data being exposed.
      • Verify that when encrypted DNS is enforced, RHEL IdM blocks unencrypted DNS queries within the internal network.
      • Verify IdM provides a fallback mechanism to log and alert administrators when encrypted DNS traffic fails to establish.
      • Verify the system supports backward compatibility with deployments that do not use DoT.
      • Verify DNS traffic encryption settings are integrated into the IdM framework, allowing configuration via CLI.

              ftrivino@redhat.com Francisco Trivino Garcia
              ftrivino@redhat.com Francisco Trivino Garcia
              Florence Renaud Florence Renaud
              Sudhir Menon Sudhir Menon
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: