Re: [dnsdist] how to increase connection qlen on DoH listener?

2020-03-30 Thread Christoph via dnsdist
> please open a feature request [1] if you > think it's worth it. thanks for considering this https://github.com/PowerDNS/pdns/issues/8986 >> Reading >> https://www.freebsd.org/doc/en/books/handbook/configtuning-kernel-limits.html >> I would expect that you want to increase kern.ipc.soacceptqu

Re: [dnsdist] A SNI with a raw IPv6 address closes the DoT connection

2020-03-30 Thread Stephane Bortzmeyer via dnsdist
On Mon, Mar 30, 2020 at 12:15:41PM +0200, Remi Gacogne via dnsdist wrote a message of 73 lines which said: > What tool are you using to test? I can't reproduce that behaviour with > openssl s_client, I can: % openssl s_client -connect dot.bortzmeyer.fr:853 -servername 2001:db8::1

Re: [dnsdist] how to increase connection qlen on DoH listener?

2020-03-30 Thread Remi Gacogne via dnsdist
Hi Christoph, On 3/29/20 8:25 PM, Christoph via dnsdist wrote: > after restarting dnsdist we noticed that while nginx takes > the new setting into account dnsdist remains at 128: > > netstat -Lan > Current listen queue sizes (qlen/incqlen/maxqlen) > Proto Listen > tcp4 0/0/128 <<< dnsdist >

Re: [dnsdist] A SNI with a raw IPv6 address closes the DoT connection

2020-03-30 Thread Remi Gacogne via dnsdist
Hello Stephane, On 3/27/20 12:20 PM, Stephane Bortzmeyer via dnsdist wrote: > I observe that sending a SNI which is a host name or an IPv4 address > works fine but when the SNI is a raw IPv6 address, the TLS connection > is immediately closed by the server. > > Is it my fault or the one of dnsdis