Open changemenemo opened 5 years ago
about the vpn part of the quesiton, it seems that my vpn is hijacking all dns queries besides those sent through some port. How would I specify port 1400 udp and 1401 tcp for example? maybe I can't specify the protocol ?
EDIT: no need to contraint unbound to certain port, I had to connect to the vpn server to a specific port to apparently not having that system put in place by the vpn provider(absurd IMO). so for the vpn part it is resolved, there is still the problem with the ssl-upstream, I suppose I didn't configure that correctly? but checkconf didn't notice me of any errors.
For the ssl-upstream setup, the config is wrong:
ssl-service-key: "/etc/ssl/certs/ca-certificates.crt"
This should be the private key, and ssl-service-pem
the public key, of your tls service (for downstream TLS, by the way, not upstream).
The ca certificates go into an option called tls-cert-bundle
, which was introduced in version 1.7.1 I think, so 1.6.0 is not going to work. For the upstream connection itself, you have to also specify where it goes, I mean, like the forward-addr destination. Here is a configuration example for tls upstream, in the 1.7.1 release anouncement. https://nlnetlabs.nl/news/2018/May/03/unbound-1.7.1-released/
Hi,
Since I haven't been able to post anything through the mailing list to get some help, I'm posting here instead.
I recently wanted to setup unbound in place of dnscrypt to resolve queries with my pi-hole on my rasp.
The version of unbound available on Raspbian is 1.6.0 currently.
When activating the options
unbound stopped working and we have something like this in the logs:
I did also try to setup unbound to send queries through a vpn connection on the rasp itself But I can’t resolve apparently through the vpn connection. I tried set it up by hardcoding the ip address from the vpn connection, same result. I tried to used udp and tcp separately, same result
Am I missing something? I have connectivity through my vpn so that’s not the problem apparently. And the problem disappear as soon as I deactivate the vpn connection. Or is all that supposed to happen in 1.6?
Does anyone have an idea about this?
Thanks in advance.