Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-07-03 Thread 'qubeslover' via qubes-users
Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Wednesday, July 3, 2019 5:24 AM, Sphere wrote: > You're welcome and good luck! > In any case, I was reminded that any sort of communication between > non-interconnected qubes are not allowed. So even if both of your

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-07-02 Thread Sphere
You're welcome and good luck! In any case, I was reminded that any sort of communication between non-interconnected qubes are not allowed. So even if both of your AppVM qubes and sys-dns qube are connected to sys-firewall then they won't be able to communicate with each other by default.

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-07-02 Thread 'qubeslover' via qubes-users
‐‐‐ Original Message ‐‐‐ On Tuesday, July 2, 2019 7:34 AM, Sphere wrote: > With my experience of using DNSCrypt I actually think that Qubes' has some > unique way of handling DNS queries given how the nameservers automatically > put into /etc/resolv.conf are on a different subnet. > >

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-07-01 Thread Sphere
With my experience of using DNSCrypt I actually think that Qubes' has some unique way of handling DNS queries given how the nameservers automatically put into /etc/resolv.conf are on a different subnet. I actually think there must be some sort of bind or unbound being ran in there that

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-07-01 Thread Chris Laprise
On 7/1/19 3:40 PM, 'qubeslover' via qubes-users wrote: Hello, I tried but without results. 1. dnf install getdns-stubby in fedora-30-firewall (template). 2. servicectl enable stubby in fedora-30-firewall. 3. Shutdown fedora-30-firewall. 4. Restart sys-firewall 4. Sudo nano /etc/resolv.conf

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-07-01 Thread 'qubeslover' via qubes-users
‐‐‐ Original Message ‐‐‐ On Sunday, June 30, 2019 11:20 PM, 'qubeslover' via qubes-users wrote: > ‐‐‐ Original Message ‐‐‐ > On Sunday, June 30, 2019 10:36 PM, Chris Laprise tas...@posteo.net wrote: > > > On 6/30/19 4:10 PM, Chris Laprise wrote: > > > > > > > A shortcut you can

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-06-30 Thread 'qubeslover' via qubes-users
‐‐‐ Original Message ‐‐‐ On Sunday, June 30, 2019 10:36 PM, Chris Laprise wrote: > On 6/30/19 4:10 PM, Chris Laprise wrote: > > > > > A shortcut you can take to setting up iptables for DNS is to populate > > > > /etc/resolv.conf and then run '/usr/lib/qubes/qubes-setup-dnat-to-ns'. > >

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-06-30 Thread Chris Laprise
On 6/30/19 4:10 PM, Chris Laprise wrote: A shortcut you can take to setting up iptables for DNS is to populate /etc/resolv.conf and then run '/usr/lib/qubes/qubes-setup-dnat-to-ns'. This should configure the nat/PR-QBS chain with the DNS addresses you set. So check that your DoT setup is

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-06-30 Thread Chris Laprise
On 6/30/19 2:46 PM, 'qubeslover' via qubes-users wrote: Dear tasket, today here is so hot that I feel like I am drunk. I typed the wrong title. The topic actually was "Dns-over-TLS in *sys-net*. Is it possible? How?" Obviously, as you correctly (and politely) pointed out, it doesn't make

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-06-30 Thread 'qubeslover' via qubes-users
Dear tasket, today here is so hot that I feel like I am drunk. I typed the wrong title. The topic actually was "Dns-over-TLS in *sys-net*. Is it possible? How?" Obviously, as you correctly (and politely) pointed out, it doesn't make sense at all to run DoT over VPN. Actually, I want to run

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-06-30 Thread Chris Laprise
On 6/30/19 9:17 AM, 'qubeslover' via qubes-users wrote: Dear qubes users, I wish you a good Sunday. I'd like to use DoT on my qubes laptop. However, I am not sure how to do. I have followed a couple of pretty straightforward tutorials

[qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-06-30 Thread 'qubeslover' via qubes-users
Dear qubes users, I wish you a good Sunday. I'd like to use DoT on my qubes laptop. However, I am not sure how to do. I have followed a couple of pretty straightforward tutorials (https://www.techrepublic.com/article/how-to-use-dns-over-tls-on-ubuntu-linux/ and