OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Revert unbound to 18.7.7 - not possible?
« previous next »
  • Print
Pages: [1] 2 3 ... 6

Author Topic: Revert unbound to 18.7.7 - not possible?  (Read 31921 times)

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Revert unbound to 18.7.7 - not possible?
« on: February 15, 2019, 03:15:38 pm »
Hello again!

Have here a fresh install of 19.1.1 amd64 with LibreSSL and DNS over TLS configured. Unbound not stable under these conditions, see here

https://forum.opnsense.org/index.php?topic=7811.msg48949#msg48949


:-(

But if I try to revert unbound to the version doing fine with 18.7.x, by

Code: [Select]
opnsense-revert -r 18.7.7 unbound
I only get "Fetching unbound.txz... failed"

(while unbound is UP und running).

Is it not possible to run 19.1.1 with this old version of unbound?

___________________

Was it only a problem with Suricata (not yet) configured correctly (and therefore not starting up)? Now Unbound has been stable for quite some time.

« Last Edit: February 15, 2019, 03:32:32 pm by chemlud »
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17705
  • Karma: 1618
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #1 on: February 15, 2019, 03:56:58 pm »
# pkg add -f https://pkg.opnsense.org/FreeBSD:11:amd64/18.7/MINT/18.7.5/LibreSSL/All/unbound-1.7.3.txz

Unbound 1.9.0 will hit 19.1.2 along with LibreSSL 2.8.3... Can't get worse in that regard I hope.


Cheers,
Franco
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #2 on: February 15, 2019, 04:02:58 pm »
... since my post unbound has been stable. Amazing!

Will try to update (fresh install + config) my systems over the weekend to see how 19.1.1 does on the different platforms :-)
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #3 on: February 15, 2019, 05:04:18 pm »
But 3 min later unbound exited on signal 11....
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #4 on: February 19, 2019, 04:10:10 pm »
Hi Franco, the command you provided downgrades unbound to 1.7.3. However, on my other LibreSSL/DNSoverTLS installs I have 1.8.1 (locked since 18.7.9), which is doing fine.

I upgrade now the 18.7.9 (via 18.7.10.4) to 19.1.1, hopefully this release will play nice with unbound 1.8.1... (otherwise will have to downgrade).
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #5 on: February 19, 2019, 04:44:02 pm »
ooops, didn't know that package lock will not survive upgrade to 19.1.1... so reverted unbound to 1.7.3.
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17705
  • Karma: 1618
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #6 on: February 19, 2019, 06:01:35 pm »
Yes, safety measure on major upgrades, otherwise things may break leaving the system in a defunct state.


Cheers,
Franco
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #7 on: February 19, 2019, 06:12:23 pm »
Meanwhile I updated 2 systems with 19.1.1/LibreSSL to unbound 1.8.1, which seems to do fine. So the problem is somewhere between 1.8.1 and 1.8.2 or 1.8.3.

Unbound 1.8.3 with DNSoverTLS is doing fine with 19.1.1 when using OpenSSL, as expected.
« Last Edit: February 19, 2019, 06:53:47 pm by chemlud »
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #8 on: February 28, 2019, 10:44:32 pm »
I updated to 19.1.2 with unbound locked to version 1.8.1. After reboot unbound simply doesn't start, nothing in the logs. I tried to replace the pkg.opnsense.org by the IP but get SSL certificate error when trying to download unbound.

No DNS here, any ideas how to resolve? 
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #9 on: March 01, 2019, 09:42:19 am »
OK, switched to DNSmasq and updated unbound to 1.9.0_1, let's see if it'S stable with DNS over TLS and LibreSSL :-)
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #10 on: March 01, 2019, 02:36:34 pm »
Update on: DNS over TLS (unbound) with LibreSSL

Apparently unbound 1.9.0_1 is stable in this setup (tested for 2-3 hours now... keep fingers crossed). :-D
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17705
  • Karma: 1618
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #11 on: March 01, 2019, 04:30:24 pm »
Not sure what went wrong here with the locked package, but keeping fingers crossed for 1.9.0 indeed...


Cheers,
Franco
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #12 on: March 02, 2019, 11:36:48 am »
...took about 24 h hours, but then exited unbound on "signal 11" according to System log...

will try to downgrade unbound and see if it starts with 19.1.2...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #13 on: March 02, 2019, 11:54:48 am »
Downgraded to unbound 1.8.1, which will not start due to

Code: [Select]
Mar 2 11:40:07 opnsense: /status_services.php: The command '/usr/local/sbin/unbound -c '/var/unbound/unbound.conf'' returned exit code '1', the output was 'Shared object "libssl.so.45" not found, required by "unbound"'
in the sys log.
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Revert unbound to 18.7.7 - not possible?
« Reply #14 on: March 02, 2019, 05:09:49 pm »
Is there sumfink like a "service watchdog" which could monitor unbound and restart if it dies away? :-)
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

  • Print
Pages: [1] 2 3 ... 6
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Revert unbound to 18.7.7 - not possible?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2