Networking notes for October 2025
Cloudflare operates the 1.1.1.1 open DNS resolver. This resolver also supports DNS over HTTPS and DNS over QUIC to protect name resolution from interception. When these protocols are used, the DNS client uses a TLS certificate for the 1.1.1.1 address to verify that it interacts with the right 1.1.1.1 server. Since the 1.1.1.1 address belongs to Cloudflare, this certificate should have been assigned to Cloudflare. However, in a blog post, Cloudflare reveals that they have detected that the Fine ÇA certification authority has issued multiple certificates for 1.1.1.1 during the last year. Even if these certificates were apparently mainly used for testing, this questions the validation process used by some certification authorities…