Re: [dnsdist] DoH issues after 1.8.3 -> 1.9.0 upgrade

2024-03-17 Thread Otto Moerbeek via dnsdist
On Sun, Mar 17, 2024 at 06:41:13PM +0100, Christoph via dnsdist wrote: > Hi, > > in February we upgraded our test DoH/DoT server from 1.8.3 to 1.9.0 > but we did not notice any problems so we upgraded our production server > from 1.8.3 to 1.9.0 yesterday. > > Immediately after upgrading our moni

Re: [dnsdist] dnsdist 1.8.0 thread spinning

2023-07-15 Thread Otto Moerbeek via dnsdist
On Fri, Jul 14, 2023 at 03:06:12PM -0500, Dustin Marquess via dnsdist wrote: > So far we've had instances with dnsdist 1.8.0 having a thread in a tight > loop. OS versions seem to vary widely, so I don't believe it's a glibc bug. > > Config on both is the same plain config: > > setLocal("127.0.

Re: [dnsdist] dnsdist latency bucket metric still broken in 1.8.0?

2023-04-14 Thread Otto Moerbeek via dnsdist
On Thu, Apr 13, 2023 at 10:00:25PM +0200, Christoph via dnsdist wrote: > Remi Gacogne via dnsdist: > > The fix not being backported is an oversight, I added the "backport to > > 1.7.x" flag so we include it in an upcoming 1.7.x release. > > Great to hear that this was unexptected. > > > > Recent

Re: [dnsdist] DNSDIST 1.8.0 With Cache Enabled Unknown key 'dontAGE'

2023-03-30 Thread Otto Moerbeek via dnsdist
On Thu, Mar 30, 2023 at 11:15:10PM +, Bradley Minamoto via dnsdist wrote: > Much thanks to Christof who pointed out the upper-case. > > My original configuration contained dontAGE=false. After correcting it to > dontAge=false the error cleared. Oddly I did not have this issue with > previou

Re: [dnsdist] DOH configuration issue

2023-03-19 Thread Otto Moerbeek via dnsdist
Oops, ignore this. My mistake. -Otto On Sun, Mar 19, 2023 at 09:14:40PM +0100, Otto Moerbeek via dnsdist wrote: > On Sun, Mar 19, 2023 at 09:09:47PM +0100, Chandra wrote: > > > Thank you. It seems I missed that one. :) > > It's good form to reply to the

Re: [dnsdist] DOH configuration issue

2023-03-19 Thread Otto Moerbeek via dnsdist
On Sun, Mar 19, 2023 at 09:09:47PM +0100, Chandra wrote: > Thank you. It seems I missed that one. :) It's good form to reply to the list. -Otto > > On Sun, Mar 19, 2023, at 21:06, Otto Moerbeek wrote: > > On Sun, Mar 19, 2023 at 04:54:19PM +0100, Chand

Re: [dnsdist] DOH configuration issue

2023-03-19 Thread Otto Moerbeek via dnsdist
On Sun, Mar 19, 2023 at 04:54:19PM +0100, Chandra via dnsdist wrote: > Hello all, > > I am trying to configure DOH over HTTP and I can't seem to figure out what > I'm doing wrong. I have a nginx proxying the incoming request and don't need > it on HTTPS. Here's my config > > *--- doh over htt

Re: [dnsdist] dnsdist not seeing a valid port

2023-01-15 Thread Otto Moerbeek via dnsdist
Hi, Can you query the recursor with dig @::1 -p 5301 ... ? If you get a timeout, it is likely an ACL isue on the recursor side, recursor will drop queries from non permitted clients. See https://docs.powerdns.com/recursor/settings.html#allow-from If so, use setVerboseHealthChecks(true) in the

Re: [dnsdist] Dnsdist dynamic backend selection between AUTH and RECURSOR

2023-01-07 Thread Otto Moerbeek via dnsdist
Hi, My first suggestion would be to not need to do the name based forwarding by separating the incoming recurosr and auth traffic on ip address or port. If that is not feasible, take a look at https://dnsdist.org/reference/kvs.html Have a process update the kv-database and dnsdist can use that t

Re: [dnsdist] Client query id in the dq-object?

2022-11-03 Thread Otto Moerbeek via dnsdist
On Wed, Nov 02, 2022 at 05:19:54PM +0100, Tom via dnsdist wrote: > Hi list > > A few months ago, I've asked the question below and wasn't able to find a > solution in the meantime. Does someone has a hint, how to achieve this? > > Many thanks in advance. > Tom > > > On 7/28/22 11:17, Tom wrote

Re: [dnsdist] Backend Questions

2022-11-02 Thread Otto Moerbeek via dnsdist
On Wed, Nov 02, 2022 at 01:38:10PM +0100, Klaus Darilion via dnsdist wrote: > (resent to the list) > > Hi Remi! > > > On 07/10/2022 10:53, Klaus Darilion via dnsdist wrote: > > > > > We use dnsdist with 1 single backend server (PDNS). So if this backend > > > is overloaded, dnsdist will detect

Re: [dnsdist] Some questions about applying for GSoC and newBPFFilter

2022-04-10 Thread Otto Moerbeek via dnsdist
On Sun, Apr 10, 2022 at 06:54:03AM +, Y7n05h via dnsdist wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On Sat, Apr 09, 2022 at 12:51:56PM +, Y7n05h via dnsdist wrote: > > Hi! > > > > I spent some time this week preparing for and participating in college > > finals (last s

Re: [dnsdist] dnsdist: use netmaskGroup with DynBlockRules exclude/includeRange

2021-07-27 Thread Otto Moerbeek via dnsdist
On Tue, Jul 27, 2021 at 01:38:08PM +, dmachard via dnsdist wrote: > Hi all, > > I am trying to use a netmaskgroup object in my DynBlockRulesGroup object with > the function "includeRange" > as introduced with the version 1.6.0 > > My config: > > nmg_internal = newNMG() > nmg_internal:addMa

Re: [dnsdist] Size of time_t error when building dnsdist 1.6.0 on armv7

2021-05-11 Thread Otto Moerbeek via dnsdist
On Tue, May 11, 2021 at 06:16:05PM +0200, Peter van Dijk via dnsdist wrote: > Hello Scott, > > On Tue, 2021-05-11 at 10:54 -0400, Scott Colby via dnsdist wrote: > > The ./configure step exits with an error: > > configure: error: size of time_t is 4, which is not large enough > > to fix the y2k38

Re: [dnsdist] cache dnsdist not working for my setup

2021-02-10 Thread Otto Moerbeek via dnsdist
On Wed, Feb 10, 2021 at 07:04:34AM +, SAMI RAHAL via dnsdist wrote: > Hi > I proceeded as Markus said the permission problem is solved but the log file > is empty and I have the following message when I want to consult the traffic > in the console. > > showResponseLatency() > No traffic yet

Re: [dnsdist] [Pdns-users] Fourth release candidate for dnsdist 1.5.0

2020-07-19 Thread Otto Moerbeek via dnsdist
On Sun, Jul 19, 2020 at 12:29:05PM +0200, Stephane Bortzmeyer via Pdns-users wrote: > On Tue, Jul 07, 2020 at 04:41:00PM +0200, > Remi Gacogne via dnsdist wrote > a message of 84 lines which said: > > > While we expected the third release candidate for dnsdist 1.5.0 to be > > the last one, a

Re: [dnsdist] how to increase connection qlen on DoH listener?

2020-03-29 Thread Otto Moerbeek via dnsdist
On Mon, Mar 30, 2020 at 08:37:24AM +0200, Otto Moerbeek via dnsdist wrote: > On Sun, Mar 29, 2020 at 06:20:00PM +, Christoph via dnsdist wrote: > > > Hi, > > > > due to log entries saying: > > "Listen queue overflow: 193 already in queue aw

Re: [dnsdist] how to increase connection qlen on DoH listener?

2020-03-29 Thread Otto Moerbeek via dnsdist
On Sun, Mar 29, 2020 at 06:20:00PM +, Christoph via dnsdist wrote: > Hi, > > due to log entries saying: > "Listen queue overflow: 193 already in queue awaiting acceptance" > we increased > kern.ipc.somaxconn to 2048 > > > after restarting dnsdist we noticed that while nginx takes > the new

Re: [dnsdist] Feature Request?

2019-08-14 Thread Otto Moerbeek
Hi, Submitting an issue to https://github.com/PowerDNS/pdns would be a first step. But it does not hurt to discuss the feature here. Maybe there's a solution to your problem possible without a new feature. -Otto On Tue, Aug 13, 2019 at 10:49:59AM -0400, Brian Sullivan wrote: > Hi, >