Must watch videos on DNS security: Stubby etc

  rs232

    rs232

    Not entirely off topic so I would invite everyone who wants to better understand what the issue is with DNS Security nowadays and what chronologically has been attempted/developed until we got to Stubby.

    I can easily say this has been the best 1 hour learning I had for long time.

    and also:

  lepa71

    lepa71

    I enabled DNSSec on my RT-AC68u running RMerlin fw. How do I test that it is working?
  rs232

    rs232

    Read in order:

    To see if the process is running:
    netstat -tulpn | grep stubby

    then inspect you "dns related" system files:

    cat /etc/resolve.conf
    cat /etc/resolv.dnsmasq
    cat /etc/dnsmasq.conf | grep "server="

    Essentially everything should point to or a there should be no reference to other DNS servers.

    NOTE: because a minor bug in tomato, you must specify DNS as manual for your WAN and fill in at least one of the two fields with This will create a duplicated entry in the dnsmasq.conf (which is irrelevant) however it will prevent from DNS ISPs from being accepted by your tomato router. If you don't though this is affecting only the router DNS resolution and not the LAN clients one.

    Also note the netstat command above is very important, you will have no name resolution until Stubby appears in the list and can take rather long time (e.g. 30 secs per se)

    The actual verification part if a bit tricky as you Stubby by default has multiple Resolvers defined (check the /etc/stubby.yml file) so you can try Cloudflare but if Stubby decides to resolve against a different (defined) resolver this page is likely to misleading you.
  lepa71

    lepa71

    I don't think RMerlin is using stubby.
  rs232

    rs232

    I don't know about DNSSEC sorry.
  rgnldo

    rgnldo

    Merlin fork 374.43 is the first FW build with native Stubby.
  Cliffield

    Cliffield

