Development issues regarding the cerowrt test router project
 help / color / mirror / Atom feed
* [Cerowrt-devel] Had to disable dnssec today
@ 2014-04-26 11:38 Aaron Wood
  2014-04-26 16:00 ` dpreed
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Aaron Wood @ 2014-04-26 11:38 UTC (permalink / raw)
  To: cerowrt-devel, dnsmasq-discuss

[-- Attachment #1: Type: text/plain, Size: 919 bytes --]

Just too many sites aren't working correctly with dnsmasq and using
Google's DNS servers.

- Bank of America (sso-fi.bankofamerica.com)
- Weather Underground (cdnjs.cloudflare.com)
- Akamai (e3191.dscc.akamaiedge.net.0.1.cn.akamaiedge.net)

And I'm not getting any traction with reporting the errors to those sites,
so it's frustrating in getting it properly fixed.

While Akamai and cloudflare appear to be issues with their entries in
google dns, or with dnsmasq's validation of them being insecure domains,
the BofA issue appears to be an outright bad key.  And BofA isn't being
helpful (just a continual "we use ssl" sort of quasi-automated response).

So I'm disabling it for now, or rather, falling back to using my ISP's dns
servers, which don't support DNSSEC at this time.  I'll be periodically
turning it back on, but too much is broken (mainly due to the cdns) to be
able to rely on it at this time.

-Aaron

[-- Attachment #2: Type: text/html, Size: 1328 bytes --]

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2014-05-17  3:58 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2014-04-26 11:38 [Cerowrt-devel] Had to disable dnssec today Aaron Wood
2014-04-26 16:00 ` dpreed
2014-04-26 16:20   ` Aaron Wood
2014-04-26 19:44     ` [Cerowrt-devel] [Dnsmasq-discuss] " Simon Kelley
2014-04-26 21:17       ` Simon Kelley
2014-04-26 23:28       ` Dave Taht
2014-04-27  2:46 ` [Cerowrt-devel] " Dave Taht
2014-05-17  3:25 ` Stephen Hemminger
2014-05-17  3:58   ` Aaron Wood

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox