From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-we0-x22e.google.com (mail-we0-x22e.google.com [IPv6:2a00:1450:400c:c03::22e]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by huchra.bufferbloat.net (Postfix) with ESMTPS id 8AC7421F298 for ; Sat, 12 Apr 2014 04:13:44 -0700 (PDT) Received: by mail-we0-f174.google.com with SMTP id t60so6351337wes.19 for ; Sat, 12 Apr 2014 04:13:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=ByGXgGv5fkYHll7TiK29sYZTzZXT6WayGwGH84/cGoI=; b=Nmkqi+X8vR5PnLaH8/eKsHL+eIWFptLoV7cGec58fDmppgkVjazE4YY7RcNy8hmHvo +DOEp7IUWrHrfw3GW8uVT9nDXo4ZVTxZ4r2fx8ZxeK/RRKhNECUaZ+9NBDgzxDAy3krf k1iMbX4ZPmLGGZSJWQuU9qZVvYoT/uxB/I3d5VrMsl6G4FasQve2ie1z9KXxThgRxIlQ 5z/GjNkPKotBCSfhmMx+rofqGap6WqZ7B/wyoCiP7ox8yWzXJ38ogFb8ZxcpmunEtJmf kQ5ql4GoB3FtrSb7GZ9wXjQX7b8EV72BdUhl4fLylwqOBYTQ/qA7Kk8pKCA5+OF9ZGkb b/RQ== X-Received: by 10.180.36.101 with SMTP id p5mr2161912wij.8.1397301222069; Sat, 12 Apr 2014 04:13:42 -0700 (PDT) Received: from ?IPv6:2001:470:6aac:1:49b4:b6e0:2511:c7e7? ([2001:470:6aac:1:49b4:b6e0:2511:c7e7]) by mx.google.com with ESMTPSA id fs16sm10025764wic.18.2014.04.12.04.13.40 for (version=TLSv1.2 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Sat, 12 Apr 2014 04:13:41 -0700 (PDT) Message-ID: <53491FD5.4020600@gmail.com> Date: Sat, 12 Apr 2014 12:13:25 +0100 From: Robert Bradley User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:24.0) Gecko/20100101 Thunderbird/24.4.0 MIME-Version: 1.0 To: cerowrt-devel References: <53491E4F.4040108@gmail.com> In-Reply-To: <53491E4F.4040108@gmail.com> X-Enigmail-Version: 1.6 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="ibX2jGxm9gfa4iUVPEa91g3IobxQ6ftOL" Subject: Re: [Cerowrt-devel] DNSSEC failure for *.cloudflare.com via dnsmasq? X-BeenThere: cerowrt-devel@lists.bufferbloat.net X-Mailman-Version: 2.1.13 Precedence: list List-Id: Development issues regarding the cerowrt test router project List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 12 Apr 2014 11:13:45 -0000 This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --ibX2jGxm9gfa4iUVPEa91g3IobxQ6ftOL Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On 12/04/2014 12:06, Robert Bradley wrote: > I noticed today that attempts to visit www.cloudflare.com and other > subdomains seem to be failing on the latest CeroWRT (3.10.36-4) when > DNSSEC checks are enabled, but not if I query Google DNS directly. If it helps, it seems to be an issue with dnssec-check-unsigned again.=20 This time though was via Google's DNS. (Using the Virgin Media DNS servers, dnssec-check-unsigned kills all DNS as per my previous posts.) --=20 Robert Bradley --ibX2jGxm9gfa4iUVPEa91g3IobxQ6ftOL Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.17 (MingW32) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iQIcBAEBAgAGBQJTSR/iAAoJEGK/UXZZ8Ak6HRYQAIiVBT0VeaP39UBPvecfPcRn p0cu9pE68Tez6++QXAMaC0GwceptyheOjw95NDDqLKzl42d7a9uDAPHMP6pcDKO6 5mDClM1sZlZ7vquacfHYd6OZMzBppujVuorXTmoojr6uf0m+ti8OEgK3Byorr3J0 a3qrT+fBQX5vbtO+TpadsqD2riXX9L00jgKdhbT11br381+kWzBWyJaa0w4a0ivz X4RypPLafqDdOeoLJRbVtyBZpOFqcqlWU9Kq3A26r+BvIdd/jidiPpqFP7WCj/M+ +nogM8lnkj5C1Fxa0WdWUEYNXHQJNqiRpyR5BGD9WvywxMsMme5IPXplpq8ZZxDe N26eqMZmx2O58vsgU/uQkc0p8j3yAEkvCiHqJuSQxqYoVOKkIw2Wk6DGZ2LkFO/0 h3nbIheRioZ2JM5BLG1cHq91mxBekLqYWN1yG9mtEy3APMdCmNd1yH5KdiI7y4c1 Kf5lUe4vvUXFJpQWY6pBimzoUMylVVYpD+xBC+j+upzcvUS9qe3r1cI7GnRMZ1QO cLvuFLQW/lKHCerN0my55eD37R2bsPbtgy+Cjb5D6ujngy5O5dBxJeo6Nmqcl3bW 6QWH2xpx+DURFyYoVbCj8WGs58cFZk6JdVRwud585qt+7qpeKSduF7QeYnoTjHWF e1JewWBUraXIReT1N4wA =eAAe -----END PGP SIGNATURE----- --ibX2jGxm9gfa4iUVPEa91g3IobxQ6ftOL--