Re: Strange issue in combination with qname-minimsation

2018-08-08 Thread Marco Davids (SIDN) via Unbound-users
Op 08-08-18 om 16:46 schreef Marco Davids (SIDN): Unbound: 1.7.1 qname: euc-word-edit.officeapps.live.com UPDATE: Problem seems gone with Unbound 1.7.3 - sorry for bothering. -- Marco signature.asc Description: OpenPGP digital signature

Strange issue in combination with qname-minimsation

2018-08-08 Thread Marco Davids (SIDN) via Unbound-users
Hi, Here is my situation: Unbound: 1.7.1 qname: euc-word-edit.officeapps.live.com Listening on IPv4 + IPv6 Steps: - Reload Unbound - Query for $qname on the IPv4 address (good reply) - Queray again for $qname on the IPv6 address (servfail) If I disable qname-minimisation it works, there are

DNAME causing problems

2018-04-18 Thread Marco Davids (SIDN) via Unbound-users
Hi, I'm running Unound 1.7.0 with all the fancy features enabled (qname minimisation, aggressive NSEC caching, the lot). When I start with an empty cache, this DNAME domain causes a SERVFAIL: dig A _sidn._dnssec-valcheck-20180418.z-347054971.bergzand.nl (same for slxh.nl) Second attempt

Compiling Unbound for algorithm 15 on Ubuntu 16.04

2017-12-07 Thread Marco Davids (SIDN) via Unbound-users
Hi, I'd like to enable support for algorithm 15 (ED25519) with Unbound on Ubuntu 16.04. Algo 16 (ED448) too, but that may not be possible. Apparently I need OpenSSL 1.1.1, which is not present on Ubuntu 16.04, or libnettle (as indicated on https://ed25519.nl/). So, I tried: ./configure

DNS over TLS

2016-10-23 Thread Marco Davids (SIDN) via Unbound-users
Hi, So I wanted to play a little with DNS over TLS and found this: forward-zone: name: "." forward-addr: 2620:ff:c000:0:1::64:25@853 Works. But trying to forward just a portion of my DNS-queries to this resolver does not seem to work, like in: forward-zone: name: "xyz"

qname-minimization for unbound-host

2016-01-29 Thread Marco Davids (SIDN) via Unbound-users
Hi, I use 'unbound-host' quit a lot for debugging. Would it be an idea to add 'qname-minimization' as an option for unbound-host, now that it is part of Unbound? Regards, -- Marco signature.asc Description: OpenPGP digital signature