[arch-commits] Commit in dnscrypt-proxy/trunk (3 files)
Date: Saturday, March 21, 2020 @ 14:32:01 Author: dvzrv Revision: 602772 upgpkg: dnscrypt-proxy 2.0.40-1: Upgrading to 2.0.40. Pulling sources by tag and verifying against upstream's PGP key: 54A2B8892CC3D6A597B92B6C210627AABA709FE1. Applying patch for configuration from separate github upstream. Setting url to current source code upstream. Adding PrivateUsers=yes and a StateDirectory (for potential DoH certificates) to the service file. Modified: dnscrypt-proxy/trunk/PKGBUILD dnscrypt-proxy/trunk/dnscrypt-proxy.service Deleted: dnscrypt-proxy/trunk/configuration.diff + PKGBUILD | 22 --- configuration.diff | 135 --- dnscrypt-proxy.service |2 3 files changed, 14 insertions(+), 145 deletions(-) Modified: PKGBUILD === --- PKGBUILD2020-03-21 14:19:55 UTC (rev 602771) +++ PKGBUILD2020-03-21 14:32:01 UTC (rev 602772) @@ -4,11 +4,11 @@ # Contributor: peace4all pkgname=dnscrypt-proxy -pkgver=2.0.39 -pkgrel=3 +pkgver=2.0.40 +pkgrel=1 pkgdesc="DNS proxy, supporting encrypted DNS protocols such as DNSCrypt v2 and DNS-over-HTTPS" arch=('x86_64') -url="https://dnscrypt.info; +url="https://github.com/DNSCrypt/dnscrypt-proxy; license=('custom:ISC') depends=('glibc') makedepends=('git' 'go-pie') @@ -21,18 +21,20 @@ "etc/${pkgname}/ip-blacklist.txt" "etc/${pkgname}/whitelist.txt" ) -source=("${pkgname}-${pkgver}.tar.gz::https://github.com/jedisct1/${pkgname}/archive/${pkgver}.tar.gz; +source=("git+https://github.com/jedisct1/${pkgname}#tag=${pkgver}?signed; "${pkgname}.service" "${pkgname}.socket" -'configuration.diff') -sha512sums=('d4eacd8d1989b99d9932d66ef609948558af26f9db1fc37acd6b5609e2a410d20828e32f2b79f2f9fbdf822998af641aec20128e4c58233663929106e29d8e24' - 'a5ec1df803436b2330861f2121fc39337cafd80cff39d29f10499ec63df7232343c249ba7ef9abbd395239d6cd482d65fd7654d196f8363feca85dd8c75f2e15' + "${pkgname}-configuration.patch::https://github.com/dvzrv/dnscrypt-proxy/commit/8d0fb58eaf5b2e315c9a243e34596104d4f2bff4.patch;) +sha512sums=('SKIP' + '9a93a2383f575cfc9c7ddbf42d075dd62877dbe50572cd853067834e0a8b66ff0173472d4b8465d357ab4cd33beedf4c39db03b8908a67180ffdb404a00a0c65' '56a56e87032da9316b392b0613124b0743673041596c717005541ae9b3994c7fc16c02497ea773d321f45d8e0f9ea8fda00783062cef4d5c8277b5b6f7cb10d5' - '456a81906c9713f7b9bdc6e152d3688899da6f760758fce91a9c625da3d7286bf0fd1d54419a57aa5ec1d9d50e1d2db32b6d5f36c2f265e227dc7e8eef65cfdd') + '3144229a4b60a237f5f576650e6f7a34df90026307bb18b68b72bddc1cbdc14f4740c29ac570e1c337ff24439172b6f6e2f0d67ec5ccd38bea1572c7ad765ebb') +validpgpkeys=('54A2B8892CC3D6A597B92B6C210627AABA709FE1') # Frank Denis (Jedi/Sector One) https://raw.githubusercontent.com/DNSCrypt/dnscrypt-resolvers/master/v2/public-resolvers.md', 'https://download.dnscrypt.info/resolvers-list/v2/public-resolvers.md'] -- cache_file = 'public-resolvers.md' -+ cache_file = '/var/cache/dnscrypt-proxy/public-resolvers.md' - minisign_key = 'RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3' - prefix = '' - -@@ -544,7 +544,7 @@ - - [sources.'relays'] - urls = ['https://raw.githubusercontent.com/DNSCrypt/dnscrypt-resolvers/master/v2/relays.md', 'https://download.dnscrypt.info/resolvers-list/v2/relays.md'] -- cache_file = 'relays.md' -+ cache_file = '/var/cache/dnscrypt-proxy/relays.md' - minisign_key = 'RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3' - refresh_delay = 72 - prefix = '' -@@ -554,7 +554,7 @@ - # [sources.quad9-resolvers] - # urls = ['https://www.quad9.net/quad9-resolvers.md'] - # minisign_key = 'RWQBphd2+f6eiAqBsvDZEBXBGHQBJfeG6G+wJPPKxCZMoEQYpmoysKUN' -- # cache_file = 'quad9-resolvers.md' -+ # cache_file = '/var/cache/dnscrypt-proxy/quad9-resolvers.md' - # prefix = 'quad9-' - - ## Another example source, with resolvers censoring some websites not appropriate for children -@@ -562,7 +562,7 @@ - - # [sources.'parental-control'] - # urls = ['https://raw.githubusercontent.com/DNSCrypt/dnscrypt-resolvers/master/v2/parental-control.md', 'https://download.dnscrypt.info/resolvers-list/v2/parental-control.md'] -- # cache_file = 'parental-control.md' -+ # cache_file = '/var/cache/dnscrypt-proxy/parental-control.md' - # minisign_key = 'RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3' - - Modified: dnscrypt-proxy.service === --- dnscrypt-proxy.service 2020-03-21 14:19:55 UTC (rev 602771) +++ dnscrypt-proxy.service 2020-03-21 14:32:01 UTC (rev 602772) @@ -16,6 +16,7 @@ NonBlocking=true NoNewPrivileges=true PrivateDevices=true +PrivateUsers=yes ProtectControlGroups=yes ProtectHome=yes ProtectHostname=yes @@ -27,6 +28,7 @@ RestrictNamespaces=true
[arch-commits] Commit in dnscrypt-proxy/trunk (3 files)
Date: Wednesday, October 3, 2018 @ 20:33:57 Author: dvzrv Revision: 389296 upgpkg: dnscrypt-proxy 2.0.17-1 Upgrading to 2.0.17. Adding further hardening to systemd service and adding ipv6 to socket. Modified: dnscrypt-proxy/trunk/PKGBUILD dnscrypt-proxy/trunk/dnscrypt-proxy.service dnscrypt-proxy/trunk/dnscrypt-proxy.socket + PKGBUILD |8 dnscrypt-proxy.service |6 +- dnscrypt-proxy.socket |2 ++ 3 files changed, 11 insertions(+), 5 deletions(-) Modified: PKGBUILD === --- PKGBUILD2018-10-03 20:17:14 UTC (rev 389295) +++ PKGBUILD2018-10-03 20:33:57 UTC (rev 389296) @@ -4,7 +4,7 @@ # Contributor: peace4all pkgname=dnscrypt-proxy -pkgver=2.0.16 +pkgver=2.0.17 pkgrel=1 pkgdesc="DNS proxy, supporting encrypted DNS protocols such as DNSCrypt v2 and DNS-over-HTTP." arch=('x86_64') @@ -24,9 +24,9 @@ "${pkgname}.service" "${pkgname}.socket" 'configuration.diff') -sha512sums=('f138df20560dd440a2ed390c1468d630191ae7b0e50521b4dde3fa7ef4377c3ae6409e8c547858bace53216c84aeeea6794305546b9ff87832f704c160c6782f' - '3b24392c1ba20a38863f2424c9d891aef84c48239340a124ee569e564f04dd06d356e03d95ef0a723c2c43a1c03c8efb3d029c99810f93ecee968e3eefbc51ea' - '17175397a5a35692f300d6caff84eb236b21a6e41a870bca966c5576f0db2bc7556d6a214d2f7e985fe9e0be99ef6e0bb067f29cebd41c2ea374540d6f4bd990' +sha512sums=('c1cb2cfff4a5f6eba81ac3b520ddb3acb311031588495b9f94a7ee5ab35ed0827a856369ce0ac7ff206445dbf24f7931cf937ccd9f724b4e38c97f10814df129' + 'aa871927bbc37d0c629e75a39cbfe50ce6062a19d7fe5b61895c604d6a480ba8f484cf207943c6ee7bf2dc3c7799d8f7a2b1ea5c8e586920c97730a7c503985e' + '56a56e87032da9316b392b0613124b0743673041596c717005541ae9b3994c7fc16c02497ea773d321f45d8e0f9ea8fda00783062cef4d5c8277b5b6f7cb10d5' '6144f3d33f3d85c9a4e5573f88e92f1b9d7118fd654072eeac6c3f76085086d4b2464e1d3579d8501153f453bc5125859d148fc3b3486d26368d1f51911aeb33') prepare() { Modified: dnscrypt-proxy.service === --- dnscrypt-proxy.service 2018-10-03 20:17:14 UTC (rev 389295) +++ dnscrypt-proxy.service 2018-10-03 20:33:57 UTC (rev 389296) @@ -7,14 +7,18 @@ [Service] NonBlocking=true ExecStart=/usr/bin/dnscrypt-proxy --config /etc/dnscrypt-proxy/dnscrypt-proxy.toml +DynamicUser=yes +ProtectSystem=strict ProtectHome=yes ProtectControlGroups=yes ProtectKernelModules=yes -DynamicUser=yes +ProtectKernelTunables=yes +LockPersonality=yes CacheDirectory=dnscrypt-proxy LogsDirectory=dnscrypt-proxy RuntimeDirectory=dnscrypt-proxy AmbientCapabilities=CAP_NET_BIND_SERVICE +NoNewPrivileges=yes [Install] WantedBy=multi-user.target Modified: dnscrypt-proxy.socket === --- dnscrypt-proxy.socket 2018-10-03 20:17:14 UTC (rev 389295) +++ dnscrypt-proxy.socket 2018-10-03 20:33:57 UTC (rev 389296) @@ -7,6 +7,8 @@ [Socket] ListenStream=127.0.0.1:53 ListenDatagram=127.0.0.1:53 +ListenStream=[::1]:53 +ListenDatagram=[::1]:53 NoDelay=true DeferAcceptSec=1
[arch-commits] Commit in dnscrypt-proxy/trunk (3 files)
Date: Friday, May 18, 2018 @ 22:44:33 Author: dvzrv Revision: 324309 upgpkg: dnscrypt-proxy 2.0.13-1 Upgrading to 2.0.13. Adding socket and service file, as upstream had just another rage quit and deleted them. Yay... Added: dnscrypt-proxy/trunk/dnscrypt-proxy.service dnscrypt-proxy/trunk/dnscrypt-proxy.socket Modified: dnscrypt-proxy/trunk/PKGBUILD + PKGBUILD | 16 ++-- dnscrypt-proxy.service | 20 dnscrypt-proxy.socket | 14 ++ 3 files changed, 44 insertions(+), 6 deletions(-) Modified: PKGBUILD === --- PKGBUILD2018-05-18 20:36:33 UTC (rev 324308) +++ PKGBUILD2018-05-18 22:44:33 UTC (rev 324309) @@ -5,7 +5,7 @@ # Contributor: peace4all pkgname=dnscrypt-proxy -pkgver=2.0.11 +pkgver=2.0.13 pkgrel=1 pkgdesc="A flexible DNS proxy, with support for modern encrypted DNS protocols such as DNSCrypt v2 and DNS-over-HTTP." arch=('x86_64') @@ -22,8 +22,12 @@ "etc/${pkgname}/whitelist.txt" ) source=("${pkgname}-${pkgver}.tar.gz::https://github.com/jedisct1/${pkgname}/archive/${pkgver}.tar.gz; +"${pkgname}.service" +"${pkgname}.socket" 'configuration.diff') -sha512sums=('5e306c3bff65d0375b650666e2191c6f54e72bb0d2d2f6f8f7b941ffc063eb7eb244a52eb69b0b008dc566e9a6ce8a8f75929edb6762fad4751d966aa2da98a0' +sha512sums=('674478118fa0324b43617c3de4637341f705da2e7346b778c3ee064e4ff09e2bfa370f451d9076804ec9b76d85a04c1e2e293ace29dcdb886f1b61fd0d8c7970' + '3b24392c1ba20a38863f2424c9d891aef84c48239340a124ee569e564f04dd06d356e03d95ef0a723c2c43a1c03c8efb3d029c99810f93ecee968e3eefbc51ea' + '17175397a5a35692f300d6caff84eb236b21a6e41a870bca966c5576f0db2bc7556d6a214d2f7e985fe9e0be99ef6e0bb067f29cebd41c2ea374540d6f4bd990' '0c6ab334eea4f295d6b86358cad9689d342c63a2cf428007df38fb1d0a72be99da79ce3775396ed410982622dce7e322326558c02d198487611ca6fa450f63f6') prepare() { @@ -60,12 +64,12 @@ install -vDm 644 "${pkgname}/example-whitelist.txt" \ "${pkgdir}/etc/${pkgname}/whitelist.txt" # systemd service/socket - install -vDm 644 "systemd/${pkgname}."{service,socket} \ --t "$pkgdir/usr/lib/systemd/system/" + install -vDm 644 "../${pkgname}."{service,socket} \ +-t "${pkgdir}/usr/lib/systemd/system/" # license - install -vDm 644 LICENSE "$pkgdir/usr/share/licenses/${pkgname}/LICENSE" + install -vDm 644 LICENSE "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE" # docs install -vDm 644 {ChangeLog,README.md} \ --t "$pkgdir/usr/share/doc/${pkgname}" +-t "${pkgdir}/usr/share/doc/${pkgname}" } # vim:set ts=2 sw=2 et: Added: dnscrypt-proxy.service === --- dnscrypt-proxy.service (rev 0) +++ dnscrypt-proxy.service 2018-05-18 22:44:33 UTC (rev 324309) @@ -0,0 +1,20 @@ +[Unit] +Description=DNSCrypt-proxy client +Documentation=https://github.com/jedisct1/dnscrypt-proxy/wiki +Wants=network-online.target nss-lookup.target +Before=nss-lookup.target + +[Service] +NonBlocking=true +ExecStart=/usr/bin/dnscrypt-proxy --config /etc/dnscrypt-proxy/dnscrypt-proxy.toml +ProtectHome=yes +ProtectControlGroups=yes +ProtectKernelModules=yes +DynamicUser=yes +CacheDirectory=dnscrypt-proxy +LogsDirectory=dnscrypt-proxy +RuntimeDirectory=dnscrypt-proxy +AmbientCapabilities=CAP_NET_BIND_SERVICE + +[Install] +WantedBy=multi-user.target Added: dnscrypt-proxy.socket === --- dnscrypt-proxy.socket (rev 0) +++ dnscrypt-proxy.socket 2018-05-18 22:44:33 UTC (rev 324309) @@ -0,0 +1,14 @@ +[Unit] +Description=DNSCrypt-proxy socket +Documentation=https://github.com/jedisct1/dnscrypt-proxy/wiki +Before=nss-lookup.target +Wants=nss-lookup.target network-online.target + +[Socket] +ListenStream=127.0.0.1:53 +ListenDatagram=127.0.0.1:53 +NoDelay=true +DeferAcceptSec=1 + +[Install] +WantedBy=sockets.target
[arch-commits] Commit in dnscrypt-proxy/trunk (3 files)
Date: Wednesday, April 4, 2018 @ 22:26:53 Author: dvzrv Revision: 314293 upgpkg: dnscrypt-proxy 2.0.8-2 Upgrading to 2.0.8. Adding new upstream url and source. Adding necessary files to backup array. Adding configuration.diff to modify the example configuration to be more FHS compliant. Updating .install file to give hint for upgrades from 1.x. Added: dnscrypt-proxy/trunk/configuration.diff Modified: dnscrypt-proxy/trunk/PKGBUILD dnscrypt-proxy/trunk/dnscrypt-proxy.install + PKGBUILD | 75 ++- configuration.diff | 111 +++ dnscrypt-proxy.install |5 +- 3 files changed, 168 insertions(+), 23 deletions(-) Modified: PKGBUILD === --- PKGBUILD2018-04-04 22:18:51 UTC (rev 314292) +++ PKGBUILD2018-04-04 22:26:53 UTC (rev 314293) @@ -1,35 +1,68 @@ # $Id$ -# Maintainer: Felix Yan+# Maintainer: David Runge +# Contributor: Felix Yan # Contributor: Techlive Zheng # Contributor: peace4all pkgname=dnscrypt-proxy -pkgver=1.9.5 -pkgrel=1 -pkgdesc="A tool for securing communications between a client and a DNS resolver" +pkgver=2.0.8 +pkgrel=2 +pkgdesc="A flexible DNS proxy, with support for modern encrypted DNS protocols such as DNSCrypt v2 and DNS-over-HTTP/2." arch=('x86_64') -url="http://dnscrypt.org/; +url="https://dnscrypt.info; license=('custom:ISC') -depends=('libsodium' 'systemd' 'libtool' 'ldns') -install=dnscrypt-proxy.install -backup=('etc/dnscrypt-proxy.conf') -source=("http://download.dnscrypt.org/$pkgname/$pkgname-$pkgver.tar.gz;) -sha512sums=('af5abcd08e3a51c1c8e142647946773c7afb4ba5076f95e74a5cbf7c54a62082de98014b6c9a1349ec6938f90d4f3584b6e6caa136902345922e16e7c9689132') +depends=('glibc') +makedepends=('git' 'go') +install="${pkgname}.install" +backup=("etc/${pkgname}/${pkgname}.toml" +"etc/${pkgname}/blacklist.txt" +"etc/${pkgname}/cloaking-rules.txt" +"etc/${pkgname}/forwarding-rules.txt" +"etc/${pkgname}/ip-blacklist.txt" +) +source=("${pkgname}-${pkgver}.tar.gz::https://github.com/jedisct1/${pkgname}/archive/${pkgver}.tar.gz; +'configuration.diff') +sha512sums=('c7e7d5d72fa6874b2b6b4deaaf6c80e4a2e812670b71bf7a308535a5773e84e249263bbb66d18fb844d8e440703facb0902f3872b117433582696695cb5a7265' + '2206b71aa05d81c962f6a93d837731946aacbcc36ee19320a9cdf379c105d04f97044be702ac83e96492ece358148227ef04ed45d17e54dd4b84f5b4d66575bf') +prepare() { + cd "$pkgname-$pkgver" + patch -Np1 -i ../configuration.diff + # create empty ip-blacklist.txt + touch "${pkgname}/ip-blacklist.txt" + # set GOPATH + export GOPATH=`pwd` + # symlink upstream's vendor to src + ln -sfv vendor src +} + build() { - cd $pkgname-$pkgver - - ./configure --prefix=/usr --sbindir=/usr/bin --sysconfdir=/etc --with-systemd - make + cd "$pkgname-$pkgver/${pkgname}" + go build -ldflags="-s -w" } package() { cd $pkgname-$pkgver - make DESTDIR="$pkgdir" install - - mkdir -p "$pkgdir"/{usr/share/{licenses,doc}/$pkgname,usr/lib/systemd/system} - install -m 644 COPYING "$pkgdir"/usr/share/licenses/$pkgname - install -m 644 AUTHORS NEWS README README.markdown "$pkgdir"/usr/share/doc/$pkgname - install -m 644 dnscrypt-proxy.service "$pkgdir"/usr/lib/systemd/system - install -m 644 dnscrypt-proxy.socket "$pkgdir"/usr/lib/systemd/system + # executable + install -vDm 755 "${pkgname}/${pkgname}" "${pkgdir}/usr/bin/${pkgname}" + # configuration + install -vDm 644 "${pkgname}/example-${pkgname}.toml" \ +"${pkgdir}/etc/${pkgname}/${pkgname}.toml" + install -vDm 644 "${pkgname}/example-blacklist.txt" \ +"${pkgdir}/etc/${pkgname}/blacklist.txt" + install -vDm 644 "${pkgname}/example-cloaking-rules.txt" \ +"${pkgdir}/etc/${pkgname}/cloaking-rules.txt" + install -vDm 644 "${pkgname}/example-forwarding-rules.txt" \ +"${pkgdir}/etc/${pkgname}/forwarding-rules.txt" + install -vDm 644 "${pkgname}/ip-blacklist.txt" \ +"${pkgdir}/etc/${pkgname}/ip-blacklist.txt" + # systemd service/socket + install -vDm 644 "systemd/${pkgname}."{service,socket} \ +-t "$pkgdir/usr/lib/systemd/system/" + # license + install -vDm 644 LICENSE "$pkgdir/usr/share/licenses/${pkgname}/LICENSE" + # docs + install -vDm 644 {ChangeLog,README.md} \ +-t "$pkgdir/usr/share/doc/${pkgname}" } +# vim:set ts=2 sw=2 et: Added: configuration.diff === --- configuration.diff (rev 0) +++ configuration.diff 2018-04-04 22:26:53 UTC (rev 314293) @@ -0,0 +1,111 @@ +diff -ruN dnscrypt-proxy-2.0.8-a/dnscrypt-proxy/example-dnscrypt-proxy.toml dnscrypt-proxy-2.0.8-b/dnscrypt-proxy/example-dnscrypt-proxy.toml +--- dnscrypt-proxy-2.0.8-a/dnscrypt-proxy/example-dnscrypt-proxy.toml 2018-03-29 11:22:20.0 +0200
[arch-commits] Commit in dnscrypt-proxy/trunk (3 files)
Date: Monday, November 18, 2013 @ 08:24:08 Author: fyan Revision: 101136 upgpkg: dnscrypt-proxy 1.3.3-3 implement FS#37775 Modified: dnscrypt-proxy/trunk/PKGBUILD dnscrypt-proxy/trunk/conf.d.file dnscrypt-proxy/trunk/dnscrypt-proxy.service + PKGBUILD | 11 +-- conf.d.file|4 dnscrypt-proxy.service |3 +++ 3 files changed, 12 insertions(+), 6 deletions(-) Modified: PKGBUILD === --- PKGBUILD2013-11-18 07:14:16 UTC (rev 101135) +++ PKGBUILD2013-11-18 07:24:08 UTC (rev 101136) @@ -5,7 +5,7 @@ pkgname=dnscrypt-proxy pkgver=1.3.3 -pkgrel=2 +pkgrel=3 pkgdesc=A tool for securing communications between a client and a DNS resolver arch=('i686' 'x86_64') url=http://dnscrypt.org/; @@ -17,13 +17,13 @@ backup=(etc/conf.d/dnscrypt-proxy) build() { - cd $srcdir/$pkgname-$pkgver + cd $pkgname-$pkgver CFLAGS=$CFLAGS -fPIC ./configure --prefix=/usr --sbindir=/usr/bin make -j2 } package() { - cd $srcdir/$pkgname-$pkgver + cd $pkgname-$pkgver make DESTDIR=$pkgdir install mkdir -p $pkgdir/{usr/share/{licenses,doc}/$pkgname,etc/conf.d,usr/lib/systemd/system} @@ -31,9 +31,8 @@ install -m 644 AUTHORS NEWS README README.markdown $pkgdir/usr/share/doc/$pkgname install -m 644 $srcdir/conf.d.file $pkgdir/etc/conf.d/$pkgname install -m 644 $srcdir/dnscrypt-proxy.service $pkgdir/usr/lib/systemd/system - rm -rf $pkgdir/usr/{lib/*.{l,}a,include} } sha512sums=('c8e9484485f060aa90a36ef097506b1042348c85b74d0e5bfdeefa8bf8f80e42ae79d4568f524bb6de0754b125ed4f4b39a177f6fdee9e4616e7d0c3641aec0b' - '2271eab1baf1a7192a8daaa1b271c24a3a3fa498432ac99c2e4fb3c939590f09aab582427ae874fce7969ece365ccb7a2e946566e5a0c650d93c34d23b536b61' - 'bfff47fc9a515a26d835e08dfeeffba07ff66b09fd887df6c961802c2f8d584f9cd05e83bdcd7ccc274215744e4a05a328aec96152dee70e2fdfe12e12b390d3') + '26e5ce3198c25ff25542dc399f2bb5467ac349dbc11c2ebd6d3ba978ffaef09607088d9401e62ba33c6f50b8b29a59f56fe97d964f55e63ee9d8ca23862c3e00' + '9a1072f83e83e55dcdd7b80d1943f60963fa240da8a50d7491cc219797c6b85b8d79d087c0f7bb9766a4d467dec58eaae2bef31b759652545ace65a6a8afb608') Modified: conf.d.file === --- conf.d.file 2013-11-18 07:14:16 UTC (rev 101135) +++ conf.d.file 2013-11-18 07:24:08 UTC (rev 101136) @@ -1,3 +1,7 @@ DNSCRYPT_LOCALIP=127.0.0.1 DNSCRYPT_LOCALPORT=53 DNSCRYPT_USER=nobody +DNSCRYPT_PROVIDER_NAME=2.dnscrypt-cert.opendns.com +DNSCRYPT_PROVIDER_KEY=B735:1140:206F:225D:3E2B:D822:D7FD:691E:A1C3:3CC8:D666:8D0C:BE04:BFAB:CA43:FB79 +DNSCRYPT_RESOLVERIP=208.67.220.220 +DNSCRYPT_RESOLVERPORT=443 Modified: dnscrypt-proxy.service === --- dnscrypt-proxy.service 2013-11-18 07:14:16 UTC (rev 101135) +++ dnscrypt-proxy.service 2013-11-18 07:24:08 UTC (rev 101136) @@ -8,6 +8,9 @@ EnvironmentFile=/etc/conf.d/dnscrypt-proxy ExecStart=/usr/bin/dnscrypt-proxy \ --local-address=${DNSCRYPT_LOCALIP}:${DNSCRYPT_LOCALPORT} \ +--resolver-address=${DNSCRYPT_RESOLVERIP}:${DNSCRYPT_RESOLVERPORT} \ +--provider-name=${DNSCRYPT_PROVIDER_NAME} \ +--provider-key=${DNSCRYPT_PROVIDER_KEY} \ --user=${DNSCRYPT_USER} Restart=on-abort