πŸ’Ύ Archived View for tilde.team β€Ί ~rami β€Ί redhat_resolved.gmi captured on 2024-08-18 at 17:35:11. Gemini links have been rewritten to link to archived content

View Raw

More Information

⬅️ Previous capture (2024-05-10)

-=-=-=-=-=-=-

~Rami β‚ͺ MANUALS

Χ¨ΧžΧ™

SUBJECT: Resolvectl (Systemd): System-wide настройка Π·Π°Ρ‰ΠΈΡ‰Π΅Π½Π½ΠΎΠ³ΠΎ Π²Π΅Ρ€ΠΈΡ„ΠΈΡ†ΠΈΡ€ΠΎΠ²Π°Π½Π½ΠΎΠ³ΠΎ соСдинСния (DNSOverTLS, DNSSEC, ECH: Encrypted Client Hello) с ΠΊΠΎΡ€Π½Π΅Π²Ρ‹ΠΌΠΈ DNS-сСрвСрами ΠΈ обСспСчСниС ΠΊΠ΅ΡˆΠΈΡ€ΠΎΠ²Π°Π½ΠΈΡ DNS-запросов Π±Π΅Π· установки стороннСго ПО

AUTHOR: Rami Rosenfeld

DATE: 07/02/24

TIME: 00.00

LANG: ru, en

LICENSE: GNU FDL 1.3

TAGS: gnu, gnome, software, opensource, linux, system, man, manual, bash, privacy, security, rhel, centos, mate, xfce, lxde, spin, de, systemd, systemctl, selinux, firewalld, dnf, rpm, ostree, flatpak, siverblue, dns, dnsovertls, dnssec, ech

Resolvectl (Systemd): System-wide настройка Π·Π°Ρ‰ΠΈΡ‰Π΅Π½Π½ΠΎΠ³ΠΎ Π²Π΅Ρ€ΠΈΡ„ΠΈΡ†ΠΈΡ€ΠΎΠ²Π°Π½Π½ΠΎΠ³ΠΎ соСдинСния (DNSOverTLS, DNSSEC, ECH: Encrypted Client Hello) с ΠΊΠΎΡ€Π½Π΅Π²Ρ‹ΠΌΠΈ DNS-сСрвСрами ΠΈ обСспСчСниС ΠΊΠ΅ΡˆΠΈΡ€ΠΎΠ²Π°Π½ΠΈΡ DNS-запросов Π±Π΅Π· установки стороннСго ПО

INTRO

Моя любимая systemd, роТдСнная Π±Π΅Π·ΡƒΠΌΠ½Ρ‹ΠΌ Π³Π΅Π½ΠΈΠ΅ΠΌ Π›Π΅Π½Π½Π°Ρ€Ρ‚ΠΎΠΌ ΠŸΠΎΡ‚Ρ‚Π΅Ρ€ΠΈΠ½Π³ΠΎΠΌ, Π½Π΅ пСрСстаСт ΡƒΠ΄ΠΈΠ²Π»ΡΡ‚ΡŒ ΠΈ Ρ€Π°Π΄ΠΎΠ²Π°Ρ‚ΡŒ своСй простотой, удобством ΠΈ Π»ΠΎΠ³ΠΈΡ‡Π½ΠΎΡΡ‚ΡŒΡŽ построСния. ΠžΠ±Ρ€Π°Ρ‚ΠΈΡ‚Π΅ особоС Π²Π½ΠΈΠΌΠ°Π½ΠΈΠ΅: всСго нСсколько ΠΏΡ€Π°Π²ΠΎΠΊ Π² ΠΊΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€Π°Ρ†ΠΈΠΎΠ½Π½ΠΎΠΌ Ρ„Π°ΠΉΠ»Π΅ - ΠΈ ΠΌΡ‹ Π°ΠΊΡ‚ΠΈΠ²ΠΈΡ€ΡƒΠ΅ΠΌ DNSOverTLS, DNSSEC ΠΈ Encrypted Client Hello для всСй ΠΎΠΏΠ΅Ρ€Π°Ρ†ΠΈΠΎΠ½Π½ΠΎΠΉ систСмы (Π° Ρ‚Π°ΠΊΠΆΠ΅ ΠΊΡΡˆΠΈΡ€ΠΎΠ²Π°Π½ΠΈΠ΅ DNS-запросов)!

Π’ΠΠ–ΠΠž! Encrypted Client Hello Π±ΡƒΠ΄Π΅Ρ‚ обСспСчСно Ρ‚ΠΎΠ»ΡŒΠΊΠΎ(!) для Ρ‚Π΅Ρ… ΠΏΡ€ΠΈΠΊΠ»Π°Π΄Π½Ρ‹Ρ… ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠΉ, ΠΊΠΎΡ‚ΠΎΡ€Ρ‹Π΅ Π΅Π³ΠΎ ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΈΠ²Π°ΡŽΡ‚! ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ см.:

Firefox: Настройка Encrypted Client Hello (Quad9)

NOTE

nano /etc/systemd/resolved.conf

DNS=9.9.9.11 149.112.112.11 2620:fe::11 2620:fe::fe:11
FallbackDNS=1.1.1.3 1.0.0.3 2606:4700:4700::1113 2606:4700:4700::1003
#Domains=
DNSSEC=yes
DNSOverTLS=yes
#MulticastDNS=no
#LLMNR=resolve
Cache=no-negative
#CacheFromLocalhost=no
#DNSStubListener=yes
#DNSStubListenerExtra=
#ReadEtcHosts=yes
#ResolveUnicastSingleLabel=no
StaleRetentionSec=86400

ОПЦИИ:

- Π‘ΡƒΠ΄ΡƒΡ‚ ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Π½Ρ‹ Π΄Π²Π° ΠΊΠΎΡ€Π½Π΅Π²Ρ‹Ρ… сСрвСра Quad9 (ipv4/6);

- Π’ качСствС Ρ€Π΅Π·Π΅Ρ€Π²Π½Ρ‹Ρ… (FallbackDNS) сСрвСров Π±ΡƒΠ΄Π΅Ρ‚ ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚ΡŒΡΡ Cloudflare;

- ΠžΠ±Ρ€Π°Ρ‚ΠΈΡ‚Π΅ Π²Π½ΠΈΠΌΠ°Π½ΠΈΠ΅: вмСсто ΠΎΠ±Ρ‰Π΅ΡƒΠΏΠΎΡ‚Ρ€Π΅Π±ΠΈΠΌΡ‹Ρ… адрСсов (9.9.9.9 ΠΈ 1.1.1.1) ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡŽΡ‚ΡΡ Π½Π΅ΠΌΠ½ΠΎΠ³ΠΎ Π΄Ρ€ΡƒΠ³ΠΈΠ΅; Π½ΠΎ ΠΎΠ½ΠΈ ΠΏΡ€Π΅Π΄ΠΎΡΡ‚Π°Π²Π»ΡΡŽΡ‚ Π½Π΅ΠΎΠ±Ρ…ΠΎΠ΄ΠΈΠΌΡ‹ΠΉ ΠΌΠ½Π΅ Ρ€Π°ΡΡˆΠΈΡ€Π΅Π½Π½Ρ‹ΠΉ Ρ„ΡƒΠ½ΠΊΡ†ΠΈΠΎΠ½Π°Π»;

- ΠžΠΏΡ†ΠΈΡ DNSSEC=yes - обСспСчиваСт ΡΠΎΠΎΡ‚Π²Π΅Ρ‚ΡΡ‚Π²ΡƒΡŽΡ‰ΡƒΡŽ Π²Π΅Ρ€ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΡŽ соСдинСния;

- ΠžΠΏΡ†ΠΈΡ DNSOverTLS=yes - Π°ΠΊΡ‚ΠΈΠ²ΠΈΡ€ΡƒΠ΅Ρ‚ ΡΠΎΠΎΡ‚Π²Π΅Ρ‚ΡΡ‚Π²ΡƒΡŽΡ‰Π΅Π΅ Π·Π°Ρ‰ΠΈΡ‰Π΅Π½Π½ΠΎΠ΅ соСдинСниС;

- ΠžΠΏΡ†ΠΈΡ Cache=no-negative - позволяСт ΡΠΎΠΊΡ€Π°Ρ‚ΠΈΡ‚ΡŒ Ρ€Π°Π·ΠΌΠ΅Ρ€ локального DNS-кэша Π·Π° счСт хранСния Ρ‚ΠΎΠ»ΡŒΠΊΠΎ соСдинСний с ΠΏΠΎΠ»ΠΎΠΆΠΈΡ‚Π΅Π»ΡŒΠ½Ρ‹ΠΌ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠΎΠΌ;

- ΠžΠΏΡ†ΠΈΡ StaleRetentionSec=86400 - обСспСчит Ρ…Ρ€Π°Π½Π΅Π½ΠΈΠ΅ записи Π² Ρ‚Π΅Ρ‡Π΅Π½ΠΈΠ΅ 24 часов (Π²Π½Π΅ зависимости ΠΎΡ‚ Π΅Π΅ "Π²Ρ€Π΅ΠΌΠ΅Π½ΠΈ ΠΆΠΈΠ·Π½ΠΈ", TLS) Π½Π° ΠΊΠΎΡ€Π½Π΅Π²ΠΎΠΌ сСрвСрС.

Π’ΠΠ–ΠΠž! ИзмСнСния Π² сСтСвых настройках ОБ ΠΏΡ€ΠΎΠΈΠ·ΠΎΠΉΠ΄ΡƒΡ‚ Ρ‚ΠΎΠ»ΡŒΠΊΠΎ послС ΠΏΠ΅Ρ€Π΅Π·Π°Π³Ρ€ΡƒΠ·ΠΊΠΈ NM ΠΈΠ»ΠΈ всСго ΠΊΠΎΠΌΠΏΡŒΡŽΡ‚Π΅Ρ€Π° (для чистоты экспСримСнта - Π½Π°ΡΡ‚ΠΎΡΡ‚Π΅Π»ΡŒΠ½ΠΎ Ρ€Π΅ΠΊΠΎΠΌΠ΅Π½Π΄ΡƒΡŽ послСднСС).

systemd-analyze cat-config systemd/resolved.conf

resolvectl status

Global
Protocols: LLMNR=resolve -mDNS +DNSOverTLS DNSSEC=yes/supported
resolv.conf mode: stub
Current DNS Server: 9.9.9.11
DNS Servers: 9.9.9.11 149.112.112.11 2620:fe::11 2620:fe::fe:11
Fallback DNS Servers: 1.1.1.3 1.0.0.3 2606:4700:4700::1113 2606:4700:4700::1003

Link 2 (enp3s0)
Current Scopes: none
Protocols: -DefaultRoute LLMNR=resolve -mDNS +DNSOverTLS DNSSEC=yes/supported

Link 3 (wlp2s0)
Current Scopes: DNS LLMNR/IPv4
Protocols: +DefaultRoute LLMNR=resolve -mDNS +DNSOverTLS DNSSEC=yes/supported
Current DNS Server: 192.168.nnn.nnn
DNS Servers: 192.168.nnn.nnn

$ resolvectl query go.dnscheck.tools

go.dnscheck.tools: 
2604:a880:400:d0::256e:b001 -- link: wlp2s0
142.93.10.179               -- link: wlp2s0

-- Information acquired via protocol DNS in 1.4529s.
-- Data is authenticated: yes; 
-- Data was acquired via local or encrypted transport: yes
-- Data from: network

resolvectl reset-statistics

resolvectl statistics

DNSSEC supported by current servers: yes

Transactions            
Current Transactions:  0
Total Transactions:  0
                        
Cache                   
Current Cache Size: 61
Cache Hits:  0
Cache Misses:  0
                        
DNSSEC Verdicts         
Secure:  0
Insecure:  0
Bogus:  0
Indeterminate:  0

resolvectl show-cache

(...)
Scope protocol=dns
org IN DS 26974 8 2 4fede294c53f438a158c (...)
. IN DNSKEY 257 3 RSASHA256 AwEAAaz/tAm8y (...)
        -- Key tag: 30903
fedoraproject.org IN A 34.221.3.152
fedoraproject.org IN A 67.219.144.68
(...)

resolvectl flush-caches

resolvectl monitor

β†’ Q: detectportal.firefox.com IN A
← S: success
← A: detectportal.firefox.com IN CNAME detectportal.prod.mozaws.net

β†’ Q: dns11.quad9.net IN A
← S: success
← A: dns11.quad9.net IN A 149.112.112.11
← A: dns11.quad9.net IN A 9.9.9.11

$ delv site.name @9.9.9.11

fully validated
site.name.		28800	IN	A	81.125.249.17
site.name.		28800	IN	RRSIG	A 8 2 86400 2024

Бинтаксис ΠΊΠΎΠΌΠ°Π½Π΄Ρ‹:

delv domain-name-here – The domain name to be looked up.

delv @dns-server-name domain-name-here – The name or IP address of the name server to query.

delv @dns-server-name domain-name-here type – State what type of DNS query is required. For example, A, AAAA, MX, TXT and so on.

Если ΠΏΡ€ΠΈ исполнСнии "ΠΊΠΎΡ€ΠΎΡ‚ΠΊΠΎΠΉ" ΠΊΠΎΠΌΠ°Π½Π΄Ρ‹ "delv site.name" Π²ΠΎΠ·Π½ΠΈΠΊΠ°Π΅Ρ‚ ошибка:

;; broken trust chain resolving 'site.name/A/IN': 127.0.0.53#53
;; resolution failed: broken trust chain

Ρ€Π΅Π·ΠΎΠ»Π²Π΅Ρ€ 127.0.0.53:53 Π½Π΅ сконфигурирован ΠΏΡ€Π°Π²ΠΈΠ»ΡŒΠ½ΠΎ для Π²Π°Π»ΠΈΠ΄Π°Ρ†ΠΈΠΈ DNSSEC. ΠŸΠΎΡΡ‚ΠΎΠΌΡƒ ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΠΉΡ‚Π΅ ΠΏΠΎΠ»Π½ΡƒΡŽ Π²Π΅Ρ€ΡΠΈΡŽ ΠΊΠΎΠΌΠ°Π½Π΄Ρ‹ (с ΡƒΠΊΠ°Π·Π°Π½ΠΈΠ΅ΠΌ ΠΊΠΎΠ½ΠΊΡ€Π΅Ρ‚Π½ΠΎΠ³ΠΎ DNS-сСрвСра), Π½Π°ΠΏΡ€ΠΈΠΌΠ΅Ρ€:

delv site.name @1.1.1.3

delv site.name @9.9.9.11

DNSSEC Resolver Test

Quad9

Cloudflare Security Check

Π”ΠΎΠΏΠΎΠ»Π½ΠΈΡ‚Π΅Π»ΡŒΠ½ΠΎ см.:

Quad9: Π‘Π΅Ρ‚Π΅Π²Ρ‹Π΅ настройки DNS

Firefox: Настройка Encrypted Client Hello (Quad9)

β‚ͺ Back to home β‚ͺ

πŸ„― Rami Rosenfeld, 2024. GNU FDL 1.3.