From: Dave Taht <dave.taht@gmail.com>
To: Aaron Wood <woody77@gmail.com>
Cc: dnsmasq-discuss <Dnsmasq-discuss@lists.thekelleys.org.uk>,
cerowrt-devel <cerowrt-devel@lists.bufferbloat.net>
Subject: Re: [Cerowrt-devel] Had to disable dnssec today
Date: Sat, 26 Apr 2014 19:46:06 -0700 [thread overview]
Message-ID: <CAA93jw7eJ+=rfZDGCzHpv1qqjBtAoW4mWPCBMhusctfNaVz-bw@mail.gmail.com> (raw)
In-Reply-To: <CALQXh-PJ+iP0r15Jewyx1wt3KWSmXNwbUME-41WM3BfXVja81g@mail.gmail.com>
On Sat, Apr 26, 2014 at 4:38 AM, Aaron Wood <woody77@gmail.com> wrote:
> Just too many sites aren't working correctly with dnsmasq and using Google's
> DNS servers.
After 4 days of uptime, I too ended up with a wedged cerowrt 3.10.36-6 on wifi.
The symptoms
were dissimilar from what has been described here - I was seeing odhcpd
trying to and failing to answer requests on the wifi interfaces, which I'd never
seen in operation before (and could have been a self-induced failure by
fiddling with hnetd)
I have merged with openwrt head, which has some hostapd and routing fixes,
as well as dnsmasq head which has some dnssec lookup fixes...
and put out cerowrt-3.10.36-7. On first boot, it had problems getting anything
on wifi to do dhcp. A reboot later (with multicast 9000 also disabled),
a kindle that was failing to get online did. This box has also never got
upstream dns servers right from the isp. I'll fiddle with the multicast thing
later, to see if that or the reboot fixed it.
With this dnssec with dnssec-check-unsigned, once time is correct:
> - Bank of America (sso-fi.bankofamerica.com)
still fails. It ain't our fault it's broke.
> - Weather Underground (cdnjs.cloudflare.com)
succeeds.
> - Akamai (e3191.dscc.akamaiedge.net.0.1.cn.akamaiedge.net)
succeeds.
> http://test-ipv6.com/
don't have ipv6 capability at this location, so this succeeds. I did see
it fail once on the first boot but haven't repeated it.
>
> And I'm not getting any traction with reporting the errors to those sites,
> so it's frustrating in getting it properly fixed.
There needs to be constant network wide scanning service of some kind
to detect dnssec configuration errors.
>
> While Akamai and cloudflare appear to be issues with their entries in google
> dns, or with dnsmasq's validation of them being insecure domains, the BofA
> issue appears to be an outright bad key. And BofA isn't being helpful (just
> a continual "we use ssl" sort of quasi-automated response).
Cluebats are needed.
> So I'm disabling it for now, or rather, falling back to using my ISP's dns
> servers, which don't support DNSSEC at this time. I'll be periodically
> turning it back on, but too much is broken (mainly due to the cdns) to be
> able to rely on it at this time.
don't blame you, but if we weren't beating it up, nobody would be.
>
> -Aaron
>
>
>
> _______________________________________________
> Cerowrt-devel mailing list
> Cerowrt-devel@lists.bufferbloat.net
> https://lists.bufferbloat.net/listinfo/cerowrt-devel
>
--
Dave Täht
NSFW: https://w2.eff.org/Censorship/Internet_censorship_bills/russell_0296_indecent.article
next prev parent reply other threads:[~2014-04-27 2:46 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-04-26 11:38 Aaron Wood
2014-04-26 16:00 ` dpreed
2014-04-26 16:20 ` Aaron Wood
2014-04-26 19:44 ` [Cerowrt-devel] [Dnsmasq-discuss] " Simon Kelley
2014-04-26 21:17 ` Simon Kelley
2014-04-26 23:28 ` Dave Taht
2014-04-27 2:46 ` Dave Taht [this message]
2014-05-17 3:25 ` [Cerowrt-devel] " Stephen Hemminger
2014-05-17 3:58 ` Aaron Wood
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: https://lists.bufferbloat.net/postorius/lists/cerowrt-devel.lists.bufferbloat.net/
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='CAA93jw7eJ+=rfZDGCzHpv1qqjBtAoW4mWPCBMhusctfNaVz-bw@mail.gmail.com' \
--to=dave.taht@gmail.com \
--cc=Dnsmasq-discuss@lists.thekelleys.org.uk \
--cc=cerowrt-devel@lists.bufferbloat.net \
--cc=woody77@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox