<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DoT support with client ID]]></title><description><![CDATA[<p dir="auto">According to Adguard wiki <a href="https://github.com/AdguardTeam/AdGuardHome/wiki/Clients#clientid" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/AdguardTeam/AdGuardHome/wiki/Clients#clientid</a>, the users client ID can be set based on the url used for DoT.</p>
<p dir="auto">I'm trying to connect to my adguard instance with <a href="http://clientID.adguard.example.com" target="_blank" rel="noopener noreferrer nofollow ugc">clientID.adguard.example.com</a> but there is a certificate mismatch because *.adguard.example.com certificates aren't being generated. See the error message below:</p>
<p dir="auto">dog <a href="http://google.com" target="_blank" rel="noopener noreferrer nofollow ugc">google.com</a> --tls @clientid.adguard.example.com<br />
Error [tls]: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:../ssl/statem/statem_clnt.c:1914: (Hostname mismatch)</p>
<p dir="auto">The main reason I want to do this is to limit DNS requests to certain clientIDs so I can use the private dns function on android. I can't use my cell IP address because it's dynamic, so that is the only way I see to have a locked down DNS server. I believe all that needs to be done is to issue certs for the adguard instance (as is already done) and then a wildcard cert for *.adguard.example.com.</p>
]]></description><link>https://forum.cloudron.io/topic/6800/dot-support-with-client-id</link><generator>RSS for Node</generator><lastBuildDate>Tue, 17 Mar 2026 05:49:03 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/6800.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 11 Apr 2022 03:52:54 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to DoT support with client ID on Sat, 15 Apr 2023 14:46:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lukas" aria-label="Profile: lukas">@<bdi>lukas</bdi></a> let's follow up at <a href="https://forum.cloudron.io/topic/9033/adguard-home-wildcard-aliases">https://forum.cloudron.io/topic/9033/adguard-home-wildcard-aliases</a></p>
]]></description><link>https://forum.cloudron.io/post/64900</link><guid isPermaLink="true">https://forum.cloudron.io/post/64900</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Sat, 15 Apr 2023 14:46:29 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Sat, 15 Apr 2023 06:54:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nichu42" aria-label="Profile: nichu42">@<bdi>nichu42</bdi></a> said in <a href="/post/64883">DoT support with client ID</a>:</p>
<blockquote>
<p dir="auto">What have you tried so far? Which Cloudron version are you running?</p>
</blockquote>
<p dir="auto">Added Client ID, like lukas-android to allow list, and added an alias lukas-android.agh.mydomain.tld to AdGuard Cloudron App. I'm running Cloudron 7.4</p>
<p dir="auto">Regards,<br />
Lukas</p>
]]></description><link>https://forum.cloudron.io/post/64885</link><guid isPermaLink="true">https://forum.cloudron.io/post/64885</guid><dc:creator><![CDATA[lukas]]></dc:creator><pubDate>Sat, 15 Apr 2023 06:54:10 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Sat, 15 Apr 2023 06:44:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lukas" aria-label="Profile: lukas">@<bdi>lukas</bdi></a> said in <a href="/post/64878">DoT support with client ID</a>:</p>
<blockquote>
<p dir="auto">is it already working? Trying to get it running but I have no success</p>
</blockquote>
<p dir="auto">Yes, it is. I have DoH and DoT enabled and restricted access to my clients. It's working great.<br />
What have you tried so far? Which Cloudron version are you running?</p>
]]></description><link>https://forum.cloudron.io/post/64883</link><guid isPermaLink="true">https://forum.cloudron.io/post/64883</guid><dc:creator><![CDATA[nichu42]]></dc:creator><pubDate>Sat, 15 Apr 2023 06:44:12 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Fri, 14 Apr 2023 22:07:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> said in <a href="/post/62451">DoT support with client ID</a>:</p>
<blockquote>
<p dir="auto">Android only supports DoT (the 'private DNS' feature). It requires a change in platform and thus will only work in next release.</p>
</blockquote>
<p dir="auto">is it already working? Trying to get it running but I have no success</p>
]]></description><link>https://forum.cloudron.io/post/64878</link><guid isPermaLink="true">https://forum.cloudron.io/post/64878</guid><dc:creator><![CDATA[lukas]]></dc:creator><pubDate>Fri, 14 Apr 2023 22:07:03 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Wed, 12 Apr 2023 15:02:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a><br />
also a big thank you from my side - the solution of software-version and adguard works like a charm</p>
]]></description><link>https://forum.cloudron.io/post/64767</link><guid isPermaLink="true">https://forum.cloudron.io/post/64767</guid><dc:creator><![CDATA[7dowWilkes]]></dc:creator><pubDate>Wed, 12 Apr 2023 15:02:48 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Sun, 02 Apr 2023 16:05:37 GMT]]></title><description><![CDATA[<p dir="auto"><s><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> mh. is there anything to do if there is already a previous version of adguard &amp; cloudron? The moment I updated both to the latest version and added an alias for the wildcard certificate, there is a mismatch between sub third and third level domain.</s></p>
<p dir="auto"><s><code>dog cloudron.io --tls @phone.adg.example.org</code><br />
Error [tls]: error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:ssl/statem/statem_clnt.c:1889: (hostname mismatch)</s></p>
<p dir="auto"><s><code>dog cloudron.io --tls @adg.example.org</code><br />
A <a href="http://cloudron.io" target="_blank" rel="noopener noreferrer nofollow ugc">cloudron.io</a>. 5m00s   165.227.67.76</s></p>
<p dir="auto">Forget about this question. I tested it with the wrong instance with v7.3</p>
]]></description><link>https://forum.cloudron.io/post/64188</link><guid isPermaLink="true">https://forum.cloudron.io/post/64188</guid><dc:creator><![CDATA[luckow]]></dc:creator><pubDate>Sun, 02 Apr 2023 16:05:37 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Fri, 31 Mar 2023 14:33:41 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a></p>
<p dir="auto">I just wanted to leave a big thank-you!<br />
DoT works perfectly with Cloudron 7.4, so I can cancel my NextDNS subscription now.</p>
]]></description><link>https://forum.cloudron.io/post/64061</link><guid isPermaLink="true">https://forum.cloudron.io/post/64061</guid><dc:creator><![CDATA[nichu42]]></dc:creator><pubDate>Fri, 31 Mar 2023 14:33:41 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Sun, 26 Feb 2023 11:01:58 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a><br />
OK, thanks. I was a bit confused by the AdGuard changelog you posted that said "Add ClientID support with DoT".<br />
So we're not waiting for an AdGuard Home release, but for the next Cloudron release.</p>
]]></description><link>https://forum.cloudron.io/post/62456</link><guid isPermaLink="true">https://forum.cloudron.io/post/62456</guid><dc:creator><![CDATA[nichu42]]></dc:creator><pubDate>Sun, 26 Feb 2023 11:01:58 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Sun, 26 Feb 2023 09:53:08 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nichu42" aria-label="Profile: nichu42">@<bdi>nichu42</bdi></a> It will only work with next cloudron release - 7.4.</p>
<p dir="auto">AdGuard supports ClientID in both DoH and DoT.</p>
<p dir="auto">DoH client id works already right now. You can use this in firefox, for example, like this (in <code>about:config</code>). Screenshot below is from desktop but maybe the mobile client supports it:</p>
<p dir="auto"><img src="/assets/uploads/files/1677405005903-93e813bb-13bd-4723-851e-a8fb9caaf708-image-resized.png" alt="93e813bb-13bd-4723-851e-a8fb9caaf708-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Android only supports DoT (the 'private DNS' feature). It requires a change in platform and thus will only work in next release.</p>
]]></description><link>https://forum.cloudron.io/post/62451</link><guid isPermaLink="true">https://forum.cloudron.io/post/62451</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Sun, 26 Feb 2023 09:53:08 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Sun, 26 Feb 2023 09:36:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a><br />
Is this supposed to work now?<br />
I installed the latest AdGuard Home version with Cloudron and set a wildcard alias (*.thirdlevel).<br />
But my Android phone is still unable to connect to <a href="http://device.thirdlevel.domain.com" target="_blank" rel="noopener noreferrer nofollow ugc">device.thirdlevel.domain.com</a></p>
<p dir="auto">Is there still something that has to be implemented on Cloudron's side or am I missing something?</p>
]]></description><link>https://forum.cloudron.io/post/62449</link><guid isPermaLink="true">https://forum.cloudron.io/post/62449</guid><dc:creator><![CDATA[nichu42]]></dc:creator><pubDate>Sun, 26 Feb 2023 09:36:54 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Mon, 30 May 2022 19:46:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/7dowwilkes" aria-label="Profile: 7dowWilkes">@<bdi>7dowWilkes</bdi></a> said in <a href="/post/48614">DoT support with client ID</a>:</p>
<blockquote>
<p dir="auto">Why can't this wildcard certificate be used for the AdGuard app?</p>
</blockquote>
<p dir="auto">The wildcard cert does not cover the bare domain cert, because of the way certs work. AdGuard also only supports one cert at a time. This means that we have to get a cert which combines the bare domain (<a href="http://foo.com" target="_blank" rel="noopener noreferrer nofollow ugc">foo.com</a>) and the wildcard (*.foo.com). Have to fix Cloudron's tls addon logic to support such an app. It's on my list.</p>
]]></description><link>https://forum.cloudron.io/post/48804</link><guid isPermaLink="true">https://forum.cloudron.io/post/48804</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Mon, 30 May 2022 19:46:53 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Thu, 26 May 2022 12:01:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> Hi, I just had the same problem as "orangetech" and the same wish to use the client id as access restriction. What I don't understand:<br />
I use my domain via netcup API and it was created for me by cloudron (probably) a wildcard certificate.<br />
Why can't this wildcard certificate be used for the AdGuard app? When I check the certificate in the AdGuard web interface, it shows me that the certificate used is only valid for the main domain.<br />
It would be nice if the client ID filtering option becomes possible.</p>
]]></description><link>https://forum.cloudron.io/post/48614</link><guid isPermaLink="true">https://forum.cloudron.io/post/48614</guid><dc:creator><![CDATA[7dowWilkes]]></dc:creator><pubDate>Thu, 26 May 2022 12:01:28 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Wed, 13 Apr 2022 16:59:04 GMT]]></title><description><![CDATA[<p dir="auto">It could also be that in ClientID mode, DoH with <code>adguard.example.com</code> is not supposed to work. Only <code>client.adguard.example.com</code> is supposed to work.</p>
<p dir="auto">In any case, apart from the certs, we also need to set up wildcard DNS.</p>
]]></description><link>https://forum.cloudron.io/post/46124</link><guid isPermaLink="true">https://forum.cloudron.io/post/46124</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Wed, 13 Apr 2022 16:59:04 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Wed, 13 Apr 2022 16:52:59 GMT]]></title><description><![CDATA[<p dir="auto">From what I could make out from the AdGuard home config, only one TLS cert can be provided. This means that the cert for <code>*.adguard.example.com</code> and <code>adguard.example.com</code> need to be combined into one cert. We have to add support for such a cert in Cloudron since we don't request combined certs.</p>
]]></description><link>https://forum.cloudron.io/post/46123</link><guid isPermaLink="true">https://forum.cloudron.io/post/46123</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Wed, 13 Apr 2022 16:52:59 GMT</pubDate></item><item><title><![CDATA[Reply to DoT support with client ID on Mon, 11 Apr 2022 21:18:59 GMT]]></title><description><![CDATA[<p dir="auto">There are apps like DNS66 and others that can set your DNS server explicitly (root) or implicitly via VPN to lock down DNS requests.</p>
<p dir="auto">Check on Fdroid.</p>
]]></description><link>https://forum.cloudron.io/post/46004</link><guid isPermaLink="true">https://forum.cloudron.io/post/46004</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Mon, 11 Apr 2022 21:18:59 GMT</pubDate></item></channel></rss>