[Touch-packages] [Bug 1857639] Re: DNS server capability detection is broken and has critical consequences when DNSSEC is enabled

2020-04-04 Thread Avamander
** Changed in: systemd (Ubuntu) Status: Incomplete => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1857639 Title: DNS server capability detection is

[Touch-packages] [Bug 1857639] Re: DNS server capability detection is broken and has critical consequences when DNSSEC is enabled

2020-01-16 Thread Avamander
``` systemd[1]: Starting Network Name Resolution... systemd-resolved[1392]: Positive Trust Anchors: systemd-resolved[1392]: . IN DS 19036 8 2 49aac11d7b6f6446702e54a1607371607a1a41855200fd2ce1cdde32f24e8fb5 systemd-resolved[1392]: . IN DS 20326 8 2

[Touch-packages] [Bug 1857639] Re: DNS server capability detection is broken and has critical consequences when DNSSEC is enabled

2020-01-07 Thread Avamander
I will need to wait for the bug to trigger again, logs have rotated since the last time I had `yes` in the config. Also, those "single line"s are actually what I did see repeatedly until I had to stop and reconfigure resolved because it made internet usage impossible. -- You received this bug

[Touch-packages] [Bug 1857639] Re: DNS server capability detection is broken and has critical consequences when DNSSEC is enabled

2020-01-07 Thread Avamander
> HOW do you have DNSSEC configured. Not a yes/no question. Actually it's exactly a "yes" in the configuration file. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1857639

[Touch-packages] [Bug 1857639] Re: DNS server capability detection is broken and has critical consequences when DNSSEC is enabled

2020-01-07 Thread Dan Streetman
> Yes, DNSSEC is configured. HOW do you have DNSSEC configured. Not a yes/no question. > Logs say this: please include more than that; single lines don't help debug. Attach the entire syslog if you're unsure how much to paste in. Also please paste/attach the output of: $ systemd-resolve

[Touch-packages] [Bug 1857639] Re: DNS server capability detection is broken and has critical consequences when DNSSEC is enabled

2020-01-07 Thread Avamander
Removed the link to a separate issue. ** No longer affects: systemd -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1857639 Title: DNS server capability detection is

[Touch-packages] [Bug 1857639] Re: DNS server capability detection is broken and has critical consequences when DNSSEC is enabled

2020-01-07 Thread Avamander
Yes, DNSSEC is configured. Logs say this: ``` Using degraded feature set (UDP+EDNS0+DO) for DNS server 192.168.1.1. ``` and then it starts to spam lines like this: ``` DNSSEC validation failed for question internetsociety.org IN A: incompatible-server ``` -- You received this bug notification

[Touch-packages] [Bug 1857639] Re: DNS server capability detection is broken and has critical consequences when DNSSEC is enabled

2020-01-07 Thread Dan Streetman
Can you post logs from when the capability mis-detection happens? What indication do you have that is what's happening? How do you have DNSSEC configured? ** Changed in: systemd (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu

[Touch-packages] [Bug 1857639] Re: DNS server capability detection is broken and has critical consequences when DNSSEC is enabled

2019-12-26 Thread Bug Watch Updater
** Changed in: systemd Status: Unknown => New -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1857639 Title: DNS server capability detection is broken and has

[Touch-packages] [Bug 1857639] Re: DNS server capability detection is broken and has critical consequences when DNSSEC is enabled

2019-12-26 Thread Avamander
** Description changed: I'm running Ubuntu 19.10 I'm on latest version available from repositories, systemd 242 I'm expecting upstream DNS server capabilities being detected correctly and DNSSEC to keep working. Alternatively I'd expect a method of disabling capability checks