We maintain security updates for the following versions:
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
We take security issues seriously. Thank you for helping us maintain the security of our add-on.
- Open a GitHub Issue
- Use the "Security" label
- Detailed description of the vulnerability
- Steps to reproduce
- Impact assessment
- Possible mitigations
- Version affected
- Any relevant screenshots or logs
- The add-on exposes DNS ports (53, 443, 853)
- Uses encrypted DNS protocols (DoH, DoT, DoQ)
- Supports SSL/TLS certificates
- Implements DNSSEC validation
- Automatic certificate generation
- Support for Let's Encrypt integration
- PKCS#12 certificate handling
- Certificate monitoring and updates
- Web interface requires authentication
- Default credentials must be changed on first login
- API access requires authentication
-
Installation
- Change default password immediately
- Use HTTPS for web interface
- Enable encrypted DNS protocols
-
Configuration
- Use Let's Encrypt certificates in production
- Enable query logging for auditing
- Regular backups of configuration
-
Network
- Restrict access to management interface
- Use firewall rules when exposed
- Monitor DNS traffic patterns