Nice! Great progress recently, but I have a basic question:

In the medium term, how do we make this work practically? Every device (or just every router?) will have a mini DNS server, which verifies that the DNS cert for npubXYZ.npub was signed by the corresponding nsec?

Reply to this note

Please Login to reply.

Discussion

You can have both worlds.

Run no-dns on localhost:53 or on your nostr:npub1zzt0d0s2f4lsanpd7nkjep5r79p7ljq7aw37eek64hf0ef6v0mxqgwljrv router

And for legacy DNS:

https://github.com/trbouma/dnspub

Both projects startet at SEC05 #soveng