Re: [Dnsmasq-discuss] AVM Fritzbox, DUalstack ISP and dnmasq

2015-01-11 Thread Rene Bartsch
- Präferenz des FRITZ!Box DHCPv6-Servers should do the trick. ;-) -- Best regards, Rene Bartsch, B. Sc. Informatics ___ Dnsmasq-discuss mailing list Dnsmasq-discuss@lists.thekelleys.org.uk http://lists.thekelleys.org.uk/mailman/listinfo/dnsmasq

[Dnsmasq-discuss] New option: --dns-rr-hexed

2014-10-10 Thread Rene Bartsch
Hi, the option --dns-rr allows to use any DNS-RR as generic type with HEX-encoded data. To simplify adding generic records I suggest to extend --dns-rr with a wrapper --dns-rr-hexed which does the encoding from ASCII to HEX. ;-) -- Best regards, Renne

Re: [Dnsmasq-discuss] Automatic DNSSEC-signing of ressource records

2014-09-15 Thread Rene Bartsch
Am 2014-09-12 19:25, schrieb Jim Gettys: On Fri, Sep 12, 2014 at 7:44 AM, Rene Bartsch m...@bartschnet.de wrote: Am 2014-09-12 10:17, schrieb Jeroen van der Ham: Ah you mean you want to use DNSmasq to do the automatic translation from DHCP leases to DNS, and then automatically sign them. I

Re: [Dnsmasq-discuss] Automatic DNSSEC-signing of ressource records

2014-09-12 Thread Rene Bartsch
Am 2014-09-12 10:17, schrieb Jeroen van der Ham: Ah you mean you want to use DNSmasq to do the automatic translation from DHCP leases to DNS, and then automatically sign them. I would still advise you to use a secondary nameserver, unless you’re not running any mission-critical systems (in

[Dnsmasq-discuss] Feature request: allow to enable/disable --dnssec-check-unsigned per upstream server

2014-08-29 Thread Rene Bartsch
Hi, I'm running Dnsmasq with DNSSEC-validation and --dnssec-check-unsigned enabled. server=/onion/127.0.0.1#9053 forwards .onion-queries to the TOR-resolver. Unfortunately the TOR-resolver provides A-RRs only. So resolving .onion-domains fails when --dnssec-check-unsigned is enabled.

[Dnsmasq-discuss] Launchpad recipe for dnsmasq with DNSSEC for Precise/Trusty

2014-08-27 Thread Rene Bartsch
Hi, I'm going to create a Dnsmasq-PPA on launchpad which provides lp:dnsmasq for Precise and Trusty with DNSSEC enabled. What do I have to change in the Launchpad recipe to build Dnsmasq with DNSSEC-support? Thanx for any hint, Renne ___

[Dnsmasq-discuss] DNS-Denial-of-Service protection via Distributed Hashtable

2014-08-22 Thread Rene Bartsch
Hi, because of the hierararchical structure of the DNS-system DDoS-attacks on nameservers or ISP-resolvers can make the internet unusable for Dnsmasq users. Taking the huge number of Dnsmasq installations into account, nearly every DNS resource record is cached on a Dnsmasq node somewhere

[Dnsmasq-discuss] Automatic DNSSEC-signing of ressource records

2014-08-22 Thread Rene Bartsch
Hi, BIND and PowerDNS can sign resource records automatically when run as primary DNS with DNSSEC. Does Dnsmasq support signing resource records automatically in authoritative mode or are there any plans to support automatic zone signing in authoritative mode? -- Best regards, Renne