OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • unbound stubby broken on LibreSSL
« previous next »
  • Print
Pages: [1]

Author Topic: unbound stubby broken on LibreSSL  (Read 3231 times)

Nekromantik

  • Jr. Member
  • **
  • Posts: 91
  • Karma: 2
    • View Profile
unbound stubby broken on LibreSSL
« on: June 30, 2019, 02:20:44 pm »
Hi
I changed to LibreSSL 19.1.9 and now Unbound and Stubby does not work.
No DNS.
Until I change unbound to use Cloudflare or Quad9.

Anyone know fix?
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: unbound stubby broken on LibreSSL
« Reply #1 on: June 30, 2019, 03:12:30 pm »
Downgrade unbound to 1.8.1. I have a thread here in the forum somewhere, franco provided the knowledge. Alternative: switch to openssl. I did the downgrade and locked unbound for now.

But the next big upgrade of opnsense might ignore the lock and than you (we) are in trouble....
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

Nekromantik

  • Jr. Member
  • **
  • Posts: 91
  • Karma: 2
    • View Profile
Re: unbound stubby broken on LibreSSL
« Reply #2 on: June 30, 2019, 03:49:27 pm »
i switched back to openssl
is    QNAME Minimisation working for you?
i cant get it to work with stubby for some reason on either openssl or libressl
« Last Edit: June 30, 2019, 03:56:10 pm by Nekromantik »
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: unbound stubby broken on LibreSSL
« Reply #3 on: June 30, 2019, 04:16:11 pm »
...sorry, no stubby here, I simply use unbound for DNS-over-TLS with LibreSSL. I didn't check what the advantages of stubby in this setup are. :-)
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: unbound stubby broken on LibreSSL
« Reply #4 on: July 03, 2019, 02:09:44 pm »
I installed 19.1.10 (libreSSL and unbound updates) and for the last 2-3 h DNS-over-TLS has been stable! :-)
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • unbound stubby broken on LibreSSL
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2