Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - bgshacklett

#1
So no, it looks like I'm just out of date on my knowledge of DNS records. Looks like this became a proposed standard, alongside SVCB records as of November 2023 (https://datatracker.ietf.org/doc/rfc9460/)?
#2
I was troubleshooting some poor DNS performance this morning and I came across a number of instances of the following message in the logs:

> error: SERVFAIL <[redacted]. HTTPS IN>: all servers for this domain failed, at zone [redacted]. upstream server timeout

Does the query type "HTTPS IN" indicate that DNS over HTTPS is in use? I haven't configured it, and I'm expecting Unbound to perform recursive lookups.

I'm currently on version 24.1.10_8 of OPNSense, with Unbound at version 1.20.0_1.