From: Dave Taht <dave.taht@gmail.com>
To: Marc Petit-Huguenin <marc@petit-huguenin.org>
Cc: "cerowrt-devel@lists.bufferbloat.net"
<cerowrt-devel@lists.bufferbloat.net>
Subject: Re: [Cerowrt-devel] [Dnsmasq-discuss] DNSSEC and www.ietf.org
Date: Sat, 11 Apr 2015 09:38:50 -0700 [thread overview]
Message-ID: <CAA93jw7Y1VrUusoZ_vLoj3oSz3JP3emPmo+f8BCcw41kT899ag@mail.gmail.com> (raw)
In-Reply-To: <552937B3.10008@petit-huguenin.org>
On Sat, Apr 11, 2015 at 8:03 AM, Marc Petit-Huguenin
<marc@petit-huguenin.org> wrote:
> On 03/30/2015 12:42 PM, Dave Taht wrote:
>> for cerowrt-3.10? Really wasn't planning on it. Didn't even know there
>> was a problem til today...
>
> So I suppose that means that Cerowrt is now unmaintained and
Yes, as funding for cerowrt has never arrived, there seems to be no
point in continuing. I put in several grant requests, none came
through, 1, is still pending, but it is very small.
I do not regard the loss of dnssec capability as worthy of updating
the 3.10.50 release, particularly when it is due to a misconfiguration
at cloudflare that they have not fixed either.
>that I should switch to something else, because my job requires near constant access to www.ietf.org and I will not disable DNSSEC.
Well it (also and ) more means that this fix to dnssec in dnsmasq are
part of dnsmasq 2.73 rc3 and later, which is not in any OS that I know
of at the moment, backports or not. There were also many, many other
fixes to dnsmasq in rc3.
There are other possible problems in dnsmasq, the most important being
a longstanding infinite loop bug that may or may not be fixed. I had
spun up 6 servers in the cloud to extensively test ipv6 and dnsmasq
and dnssec and edns0 etc - but did not find sufficient time to tackle
the problem myself and am leaving for vacation today.
If anyone here wants to configure namebench to go through the alexa
top 1million over and over again, using ipv6 primarily, and do other
stress test benchmarks like that against r2.73c3 and later - send me
your ssh keys - or please spin up your own servers in a cloud with
ipv6 in it (like linode), and/or dogfood elsewhere.
> So, what would you recommend for my WNDR3800?
Openwrt chaos calmer. Still won't solve your problem til someone gets
around to testing the patches and pushing them into openwrt.
I am taking my guitar and going off to this:
http://en.wikipedia.org/wiki/SpaceX_CRS-6
My backup plan, in case the internet failed, was always to get off planet.
I am quite fond of the Arkyd-3.
>
> Thanks.
>
>>
>> for my current openwrt builds - you betcha. thursday-ish.
>>
>> On Mon, Mar 30, 2015 at 11:17 AM, Marc Petit-Huguenin
>> <marc@petit-huguenin.org> wrote:
>>> On 03/30/2015 11:49 AM, Simon Kelley wrote:
>>>> Dnsmasq bug, should be fixed in 2.73rc3 pls shout if not.
>>>>
>>>> (the problem is that the clouldflare.bet zone includes the domains
>>>> /003.cloudflare.net (that's ctrl-c at the start) and that was
>>>> confusing dnsmasq.)
>>>
>>> Thanks.
>>>
>>> Dave, any chance to get a build of 2.73rc3?
>>>
>>>>
>>>> Simon.
>>>>
>>>>
>>>>
>>>> On 30/03/15 16:58, Dave Taht wrote:
>>>>> I have trouble accessing ietf.org, also, with older versions of
>>>>> dnsmasq + dnssec, presently.
>>>>
>>>>> On Mon, Mar 30, 2015 at 8:52 AM, Marc Petit-Huguenin
>>>>> <marc@petit-huguenin.org> wrote:
>>>>>> Am I the only one who cannot access www.ietf.org since Cloudflare
>>>>>> enabled DNSSEC? (with dnsmasq-full 2.73-3)
>>>>>>
>>>>>> Thanks.
>>>>>>
>
> --
> Marc Petit-Huguenin
> Email: marc@petit-huguenin.org
> Blog: http://blog.marc.petit-huguenin.org
> Profile: http://www.linkedin.com/in/petithug
>
--
Dave Täht
Let's make wifi fast, less jittery and reliable again!
https://plus.google.com/u/0/107942175615993706558/posts/TVX3o84jjmb
prev parent reply other threads:[~2015-04-11 16:38 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-03-30 15:52 [Cerowrt-devel] " Marc Petit-Huguenin
2015-03-30 15:58 ` Dave Taht
2015-03-30 16:19 ` David Personette
2015-03-30 17:49 ` [Cerowrt-devel] [Dnsmasq-discuss] " Simon Kelley
2015-03-30 18:17 ` Marc Petit-Huguenin
2015-03-30 18:42 ` Dave Taht
2015-04-11 15:03 ` Marc Petit-Huguenin
2015-04-11 16:32 ` Kevin Darbyshire-Bryant
2015-04-11 16:49 ` Dave Taht
2015-04-11 19:13 ` Kevin Darbyshire-Bryant
2015-04-13 14:02 ` Marc Petit-Huguenin
2015-04-11 16:38 ` Dave Taht [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: https://lists.bufferbloat.net/postorius/lists/cerowrt-devel.lists.bufferbloat.net/
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=CAA93jw7Y1VrUusoZ_vLoj3oSz3JP3emPmo+f8BCcw41kT899ag@mail.gmail.com \
--to=dave.taht@gmail.com \
--cc=cerowrt-devel@lists.bufferbloat.net \
--cc=marc@petit-huguenin.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox