Re: Introducing CurveDNS a DNSCurve forwarding name server

Hauke Lampe <[email protected]> Sun, 24 Oct 2010 08:15:45 +0200
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


On 23.10.2010 20:14, Harm van Tilborg wrote:

> We are happy to announce the first forwarding DNSCurve solution: CurveDNS.

Nice work.

I installed it on a test server:

dig curvetest.openchaos.org SOA
(fwiw, the zone is also DNSSEC-signed, verifiable via dlv.isc.org)

I had a problem at first where curvedns would bind the listening ports
but could not forward UDP queries when not run as root.
That problem vanished somehow, I don't know why.

A more serious problem was that curvedns did not select a specific
outbound address and I need it to do that, so the authoritative
nameserver responds from the correct view.

I patched it to use the first local address of matching address family,
but it would probably be better if the outgoing addresses could be
configured separately:
https://www.hauke-lampe.de/linkedstuff/curvedns-0.86-outgoing-addr.patch

Ubuntu users find binary and source packages here:
https://launchpad.net/~hauke/+archive/dnscurve/+packages



Hauke.


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkzDzwwACgkQKIgAG9lfHFOyCACgsfqisO1r3RHRQZgZ6FjeZwf8
qrsAn0L8dORWxQEw9cbnJUnzr2Au6xBA
=8WQf
-----END PGP SIGNATURE-----