Re: [Dnsmasq-discuss] [Cerowrt-devel] Had to disable dnssec today

2014-04-26 Thread Dave Taht
On Sat, Apr 26, 2014 at 4:38 AM, Aaron Wood wrote: > Just too many sites aren't working correctly with dnsmasq and using Google's > DNS servers. After 4 days of uptime, I too ended up with a wedged cerowrt 3.10.36-6 on wifi. The symptoms were dissimilar from what has been described here - I was

Re: [Dnsmasq-discuss] [Cerowrt-devel] Had to disable dnssec today

2014-04-26 Thread Dave Taht
On Sat, Apr 26, 2014 at 12:44 PM, Simon Kelley wrote: > On 26/04/14 17:20, Aaron Wood wrote: >> David, >> >> With two of them (akamai and cloudflare), I _think_ it's a dnsmasq >> issue with the DS records for proving insecure domains are insecure. >> But Simon Kelley would know that better than I.

Re: [Dnsmasq-discuss] [Cerowrt-devel] Had to disable dnssec today

2014-04-26 Thread Simon Kelley
On 26/04/14 20:44, Simon Kelley wrote: > I plan to see if dnsmasq can be modified to improve this. In the git repo now, the change allows the akamai domain to resolve successfully. Simon. ___ Dnsmasq-discuss mailing list Dnsmasq-discuss@lists.thekel

Re: [Dnsmasq-discuss] [Cerowrt-devel] Had to disable dnssec today

2014-04-26 Thread Simon Kelley
On 26/04/14 17:20, Aaron Wood wrote: > David, > > With two of them (akamai and cloudflare), I _think_ it's a dnsmasq > issue with the DS records for proving insecure domains are insecure. > But Simon Kelley would know that better than I. > The result of the analysis of the akamai domain was t

Re: [Dnsmasq-discuss] [Cerowrt-devel] Had to disable dnssec today

2014-04-26 Thread Aaron Wood
David, With two of them (akamai and cloudflare), I _think_ it's a dnsmasq issue with the DS records for proving insecure domains are insecure. But Simon Kelley would know that better than I. With BofA, I'm nearly certain it's them, or an issue with one of their partners (since the domain that fa

[Dnsmasq-discuss] Had to disable dnssec today

2014-04-26 Thread Aaron Wood
Just too many sites aren't working correctly with dnsmasq and using Google's DNS servers. - Bank of America (sso-fi.bankofamerica.com) - Weather Underground (cdnjs.cloudflare.com) - Akamai (e3191.dscc.akamaiedge.net.0.1.cn.akamaiedge.net) And I'm not getting any traction with reporting the errors