[Dnsmasq-discuss] Starting as non-root

2019-05-13 Thread Kristoffel Pirard
Hi there, The dnsmasq man page for the --user parameter says that "Dnsmasq must _normally_ be started as root". We tested starting as non-root user, but with capabilities cap_net_bind_service, cap_net_admin, cap_net_raw. It currently seems to work, but I'm debating if we should actually use

Re: [Dnsmasq-discuss] Starting as non-root

2019-05-13 Thread Kristoffel Pirard
So I should interpret it as 'unless you have a really good reason and you know what you're doing'? (Which I answer 'no' to twice) On Mon, 13 May 2019, 12:36 Geert Stappers, wrote: > > On 13-05-2019 11:02, Roy Marples wrote: > > On 13/05/2019 09:31, Kristoffel Pirard wrote: > >> The dnsmasq man

Re: [Dnsmasq-discuss] Starting as non-root

2019-05-13 Thread Geert Stappers
On 13-05-2019 11:02, Roy Marples wrote: > On 13/05/2019 09:31, Kristoffel Pirard wrote: >> The dnsmasq man page for the --user parameter says that "Dnsmasq must >> _normally_ be started as root".  We tested starting as non-root user, >> but with capabilities cap_net_bind_service, cap_net_admin,

[Dnsmasq-discuss] Insecure DS reply warning - false positives?

2019-05-13 Thread Kevin Darbyshire-Bryant
Hi All, Part of the reason for submitting http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2019q2/013026.html "[PATCH] dnssec: add hostname info to insecure DS warning” was to easily find out what domain was prompting the warning. Some of my mystery ‘Insecure DS reply’ turns out to be

Re: [Dnsmasq-discuss] Starting as non-root

2019-05-13 Thread Roy Marples
On 13/05/2019 09:31, Kristoffel Pirard wrote: The dnsmasq man page for the --user parameter says that "Dnsmasq must _normally_ be started as root".  We tested starting as non-root user, but with capabilities cap_net_bind_service, cap_net_admin, cap_net_raw. It currently seems to work, but I'm

Re: [Dnsmasq-discuss] Starting as non-root just works

2019-05-13 Thread Geert Stappers
On Mon, May 13, 2019 at 12:51:09PM +0200, Kristoffel Pirard wrote: > On Mon, 13 May 2019, 12:36 Geert Stappers wrote: > > On 13-05-2019 11:02, Roy Marples wrote: > > > On 13/05/2019 09:31, Kristoffel Pirard wrote: > > >> The dnsmasq man page for the --user parameter says that "Dnsmasq must > > >>

[Dnsmasq-discuss] dnsmasq dies after about 20 minutes

2019-05-13 Thread Steve Lloyd
I am running dnsmasq on the lastest stretch on a rpi. For some reason dnsmasq dies after about 20 minutes, I can restart it and it will last another 20 minutes. Any insight on how to fix this would be much appreciated. Here is the status after it dies, followed by the resolvconf.conf