COllaborative DEcision MAking (codema.in)

Setup Private Dns With Open Nic Servers

Pirate Praveen Wed 5 Aug 2020 10:22AMPublicSeen by 70

Created a blog post for setting up Private DNS in Android 9+ using DoT and Open NIC servers.

https://fsci.in/blog/setup-private-dns-with-open-nic-servers/

You can leave comments or improvements here.

Pirate PraveenSun 4 Oct 2026 6:45PM

@Badri Sunderarajan tls support is still experimental and complicated, so that limits its usefulness a lot. https://wiki.opennic.org/opennic/tls

Badri SunderarajanMon 5 Oct 2026 3:40AM

@Pirate Praveen right, this makes it a bit more complex but I think most of the complexity is on the server operators' side. We basically have to install the root certificate once, and possibly tell certbot to update it when needed. This would be simple on servers running Apache2 or nginx, though it may be complicated in Caddy unless it's written to account for supporting such things already.

@Derpitron could tell us after setting up OpenNIC on their homelab. I am also thinking of setting it up, so if that happens first I'll report back. Either way, we'll have a clearer picture of how complex it is and we can take a call w.r.t. FSCI based on that. If we decide to go ahead, we can do it on some nginx powered server first (maybe the git one I am already part of the volunteers for?) and get to Caddy later.

AkshayMon 5 Oct 2026 4:41AM

@Badri Sunderarajan why will we need nginx? Is there more than one idea being discussed here?

Badri SunderarajanMon 5 Oct 2026 4:49AM

@Akshay I meant that Caddy tries to handle certificates on its own which may accidentally interfere with what we try to do with OpenNIC certificates. (It may not either, since we're talking about root certificates not signing ones, I'm just bringing it up as something to be checked). s/nginx/anything other than Caddy/g

AkshayMon 5 Oct 2026 4:52AM

@Badri Sunderarajan I don't think caddy/nginx has anything to do with this. We will need jitsi/prosody/postfix/etc to recognize the root CA we install to our system rather than use their own internal root CAs. (I think only browsers do that vendoring of roots and the apps will just rely on openssl or something)

Badri SunderarajanMon 5 Oct 2026 4:59AM

@Akshay right, that makes more sense!