Development of a DoT/DoH name server with parental control functionality
Budget: €3,000 – €5,000 EUR
We already run a name server with parental control functionality (see: jusprogdns.com) giving “wrong” response to browsers used by kids and schools in case they request the IP for a domain not suitable for minors. The idea is similar to the wellknown OpenDNS (opendns.com).
Now we like to build a name server with DoT and DoH (DNS over TLS / HTTPS) as a separate application only connected via API to the existing jusprogdns.com name server.
# What is your task?
Development of the DoT / DoH name server resolving client requests with DNS over HTTPS as well as DNS over TLS ready to run and implemented on one of our Linux servers .
Main Features:
- Name server reacts to four different age groups (website suitable from 0 / 6 / 12 / 16 years) depending on the risk potential for minors of the website requested at the name server
- Name server reacts in this alternative ways: a) response to kids client (browser) with the right IP address in case the website is suitable for the age group b) response with “no ip address” in case https website is not suitable for minors and must in fact be blocked c) gives a “wrong” standard IP address redirecting to an information server in case a http website should be blocked.
- Requests from kids clients (browser) comes from together eight different subdomains: one for each age group for DoT and one for each age group for DoH. The subdomain marks the age group the kid is surfing with.
- The information how to deal with a requested website (FQDN) comes via our already existing API (implemented in the jusprogdns.com system) including the right IP address of the requested website in case the website is suitable for kids.
- Sync of the entire system to a 2nd server for performance and failure risc (behind load balancer). Mirror in a 2nd data center.
# How is it supposed to work with the API?
The DoT / DoH application sends a request object to the API, which in turn returns the answer of the requested DNS record type (code 200).
The request can also be blocked within the API. If thats the case the API returns the answer object but with the value “false” (code 201).
Should the request have errors or if required parameters are missing, the API will reject the request (code 400).
We provide an API description. The API is secured to not allowed use by someone else (via token and IP check).
# Technical conditions:
The DoT / DoH application needs to be written with either PHP 7.3 (v7.3.4-2) or node.js (v10.15.2).
For PHP please note that there is the possibility for an update to PHP 8.
Even for node.js there is a possibility for future updates. So please make sure to write future proof code.
If a database is needed use either mongodb (v4.0.10) or mariadb (10.3.15-MariaDB-1-log Debian 10).
Only open source and free standard libraries are used.
We get a technical documentation (English) in e.g. MS Word and lots of inline comments.
# Project conditions:
Three weeks from assignment the application must be running on your dev server and must be ready to test for us (milestone 1). After successful testing one more week for implementation on our server ready for go-live (ms 2) plus another week for documentation (ms3 and finish)
75 % of payment is due when application is ready for go-live and 25 % when documentation is done and project is finished. If the time schedule is overdue by more than 50 % of one mile stone period we have the right to cancel the order without any costs.
With our payment we alone own the source code after end of project (nothing encrypted), you don’t have the right to use the source code in other ways or publish parts of it.
# Who are we?
JusProg e.V. (www.jugendschutzprogramm.de) is a non-profit organization (NGO) that has set itself the task of better protecting children on the internet. We provide a youth protection / parental control software free to use.
Thank you in advance for your help in making the internet a better and safer place for kids!
Now we like to build a name server with DoT and DoH (DNS over TLS / HTTPS) as a separate application only connected via API to the existing jusprogdns.com name server.
# What is your task?
Development of the DoT / DoH name server resolving client requests with DNS over HTTPS as well as DNS over TLS ready to run and implemented on one of our Linux servers .
Main Features:
- Name server reacts to four different age groups (website suitable from 0 / 6 / 12 / 16 years) depending on the risk potential for minors of the website requested at the name server
- Name server reacts in this alternative ways: a) response to kids client (browser) with the right IP address in case the website is suitable for the age group b) response with “no ip address” in case https website is not suitable for minors and must in fact be blocked c) gives a “wrong” standard IP address redirecting to an information server in case a http website should be blocked.
- Requests from kids clients (browser) comes from together eight different subdomains: one for each age group for DoT and one for each age group for DoH. The subdomain marks the age group the kid is surfing with.
- The information how to deal with a requested website (FQDN) comes via our already existing API (implemented in the jusprogdns.com system) including the right IP address of the requested website in case the website is suitable for kids.
- Sync of the entire system to a 2nd server for performance and failure risc (behind load balancer). Mirror in a 2nd data center.
# How is it supposed to work with the API?
The DoT / DoH application sends a request object to the API, which in turn returns the answer of the requested DNS record type (code 200).
The request can also be blocked within the API. If thats the case the API returns the answer object but with the value “false” (code 201).
Should the request have errors or if required parameters are missing, the API will reject the request (code 400).
We provide an API description. The API is secured to not allowed use by someone else (via token and IP check).
# Technical conditions:
The DoT / DoH application needs to be written with either PHP 7.3 (v7.3.4-2) or node.js (v10.15.2).
For PHP please note that there is the possibility for an update to PHP 8.
Even for node.js there is a possibility for future updates. So please make sure to write future proof code.
If a database is needed use either mongodb (v4.0.10) or mariadb (10.3.15-MariaDB-1-log Debian 10).
Only open source and free standard libraries are used.
We get a technical documentation (English) in e.g. MS Word and lots of inline comments.
# Project conditions:
Three weeks from assignment the application must be running on your dev server and must be ready to test for us (milestone 1). After successful testing one more week for implementation on our server ready for go-live (ms 2) plus another week for documentation (ms3 and finish)
75 % of payment is due when application is ready for go-live and 25 % when documentation is done and project is finished. If the time schedule is overdue by more than 50 % of one mile stone period we have the right to cancel the order without any costs.
With our payment we alone own the source code after end of project (nothing encrypted), you don’t have the right to use the source code in other ways or publish parts of it.
# Who are we?
JusProg e.V. (www.jugendschutzprogramm.de) is a non-profit organization (NGO) that has set itself the task of better protecting children on the internet. We provide a youth protection / parental control software free to use.
Thank you in advance for your help in making the internet a better and safer place for kids!