desktop-packages team mailing list archive
-
desktop-packages team
-
Mailing list archive
-
Message #154919
[Bug 995332] Re: Please enhance NetworkManager such that DNSSEC validation is done whenever possible
On Wily, I edited /etc/dnsmasq.d/network-manager and added the following
lines:
# DNSSEC setup
dnssec
trust-anchor=.,19036,8,2,49AAC11D7B6F6446702E54A1607371607A1A41855200FD2CE1CDDE32F24E8FB5
dnssec-check-unsigned
I then restarted network-manager and tried to connect to http://www.dnssec-failed.org/.
As expected, the site does not load (it is deliberately configured to fail DNSSEC validation).
But when reloading the page multiple-time, it is sometime displayed! I don't understand why.
--
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to network-manager in Ubuntu.
https://bugs.launchpad.net/bugs/995332
Title:
Please enhance NetworkManager such that DNSSEC validation is done
whenever possible
Status in dnsmasq package in Ubuntu:
Invalid
Status in network-manager package in Ubuntu:
Triaged
Bug description:
Network Manager in Precise uses a local forwarding DNS server
(dnsmasq). This does not perform DNSSEC validation, although it is
configured to proxy the DNSSEC validation result from the upstream
server, for which the manpage mentions the following caveat:
"You should only do this if you trust all the configured upstream
nameservers and the network between you and them."
Since not all networks or upstream DNS servers are trustworthy, the
safest place to perform DNSSEC validation is on the client. Using a
local DNS server which cannot validate is a missed opportunity; by
replacing dnsmasq with a more-capable DNS server (e.g. Unbound)
security against DNS poisoning and MITM attacks could be improved.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/dnsmasq/+bug/995332/+subscriptions