Update docs

This commit is contained in:
Pothi Kalimuthu 2023-08-25 11:24:56 +05:30
parent 7d8ec6c113
commit 650e51e378
No known key found for this signature in database
GPG key ID: 08202A469C2D0E06

View file

@ -1,20 +1,23 @@
TODO: The following DoH services can be automated for now...
- DoH script for nextdns - [Cloudflare](https://github.com/pothi/mikrotik-scripts/blob/main/doh-scripts/cloudflare.rsc)
- [Google](https://github.com/pothi/mikrotik-scripts/blob/main/doh-scripts/google.rsc)
- [NextDNS](https://github.com/pothi/mikrotik-scripts/blob/main/doh-scripts/nextdns.rsc)
- [Quad9](https://github.com/pothi/mikrotik-scripts/blob/main/doh-scripts/quad9.rsc)
Important thread... https://forum.mikrotik.com/viewtopic.php?f=2&t=160243#p799274 Or you may use the [generic script](https://github.com/pothi/mikrotik-scripts/blob/main/doh-scripts/generic.rsc).
Relevant thread in MikroTik forums... https://forum.mikrotik.com/viewtopic.php?f=2&t=160243#p799274
Remember that DoH depends on correct time. So, make sure NTP client is configured. The MikroTik Cloud NTP client service required DNS that in turn requires a working NTP client. So, don't depend on MikroTik Cloud NTP client service. Remember that DoH depends on correct time. So, make sure NTP client is configured. The MikroTik Cloud NTP client service required DNS that in turn requires a working NTP client. So, don't depend on MikroTik Cloud NTP client service.
NextDNS recommends https://curl.se/ca/cacert.pem too.
Root CA certificates that we can use... Root CA certificates that we can use...
- https://www.digicert.com/kb/digicert-root-certificates.htm (Download DigiCert Global Root CA) - https://www.digicert.com/kb/digicert-root-certificates.htm (Download DigiCert Global Root CA)
- https://cacerts.digicert.com/DigiCertGlobalRootCA.crt.pem - https://cacerts.digicert.com/DigiCertGlobalRootCA.crt.pem
- works **only** for 1.1.1.1 DoH - works **only** for 1.1.1.1 DoH
# the following don't work for unknown reason... The following don't work for unknown reason...
- https://pki.goog/repository/ - https://pki.goog/repository/
- https://support.globalsign.com/ca-certificates/root-certificates/globalsign-root-certificates - https://support.globalsign.com/ca-certificates/root-certificates/globalsign-root-certificates
@ -23,3 +26,6 @@ Root CA certificates that we can use...
Or download most (if not all) root CA certificates from https://curl.se/ca/cacert.pem Or download most (if not all) root CA certificates from https://curl.se/ca/cacert.pem
Recommended - https://pki.goog/repo/certs/gtsr4.pem (validity: 2038) Recommended - https://pki.goog/repo/certs/gtsr4.pem (validity: 2038)
NextDNS recommends https://curl.se/ca/cacert.pem too.