OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • [SOLVED] ssl handshake errors between unbound and DNSoverTLS enabled forwarders
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] ssl handshake errors between unbound and DNSoverTLS enabled forwarders  (Read 9320 times)

rookie

  • Newbie
  • *
  • Posts: 8
  • Karma: 1
    • View Profile
[SOLVED] ssl handshake errors between unbound and DNSoverTLS enabled forwarders
« on: March 07, 2019, 08:10:15 pm »
I upgraded my firewall from 18.7.10 to 19.1.2. Now I have an issue with unbound and forwarders via DNSoverTLS.
Unbound starts and is listening on all ips but doesn't resolv any requested names. The unbound log has entries like this:

[1551968079] unbound[33902:1] debug: iterator[module 1] operate: extstate:module_state_initial event:module_event_pass         
[1551968079] unbound[33902:1] info: resolving 0.freebsd.pool.ntp.org. AAAA IN                                                   
[1551968079] unbound[33902:1] info: processQueryTargets: 0.freebsd.pool.ntp.org. AAAA IN                                       
[1551968079] unbound[33902:1] info: sending query: 0.freebsd.pool.ntp.org. AAAA IN                                             
[1551968079] unbound[33902:1] debug: sending to target: <.> 9.9.9.9#853                                                         
[1551968079] unbound[33902:1] debug: cache memory msg=132120 rrset=132120 infra=10617 val=132336                               
[1551968079] unbound[33902:1] error: ssl handshake failed crypto error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed                                                                                                             
[1551968079] unbound[33902:1] notice: ssl handshake failed 9.9.9.9 port 853                                                     
[1551968079] unbound[33902:1] debug: outnettcp got tcp error -1                                                                 
[1551968079] unbound[33902:1] debug: tcp error for address 9.9.9.9 port 853                                                     
[1551968079] unbound[33902:1] debug: iterator[module 1] operate: extstate:module_wait_reply event:module_event_noreply

The happens with flavour default and OpenSSL. I didn't try LibreSSL, because I had problems with it under FreeBSD in the past and switched back to OpenSSL.

I reinstalled the ca_root_nss package without luck.

Any ideas how can I solve this issue?
« Last Edit: March 08, 2019, 10:25:15 pm by rookie »
Logged

newsense

  • Hero Member
  • *****
  • Posts: 1038
  • Karma: 77
    • View Profile
Re: ssl handshake errors between unbound and DNSoverTLS enabled forwarders
« Reply #1 on: March 08, 2019, 07:21:39 am »
Code: [Select]
[1551968079] unbound[33902:1] error: ssl handshake failed crypto error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed                                                                                                              Failure to verify certs could be indicative of time being improperly set. Add 1.1.1.1 as a system dns resolver and make sure you can sync NTP clock first
Logged

rookie

  • Newbie
  • *
  • Posts: 8
  • Karma: 1
    • View Profile
Re: ssl handshake errors between unbound and DNSoverTLS enabled forwarders
« Reply #2 on: March 08, 2019, 09:05:16 pm »
Thanks for your answer but it didn't help. The system clock is in sync.
Logged

rookie

  • Newbie
  • *
  • Posts: 8
  • Karma: 1
    • View Profile
[SOLVED] ssl handshake errors between unbound and DNSoverTLS enabled forwarders
« Reply #3 on: March 08, 2019, 10:24:43 pm »
I found a solution for my issue. I added following line to a server block and afterwards the name resolution works.

Code: [Select]
tls-cert-bundle: /etc/ssl/cert.pem
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • [SOLVED] ssl handshake errors between unbound and DNSoverTLS enabled forwarders
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2