Good morning. As promised I've turned off regular cleartext port 53 DNS on all servers. Switch to DoT or DoH to keep using the servers. Check this repo for guides on how to do so: https://t.co/USFqyD0qEX See a guide is missing? Make a PR! <3
We are almost half way through a 12 hour brownout to prepare everyone for this change https://t.co/iUFPcOeRGn
Plaintext DNS will work again from tonight at 20:00 CEST, and will be turned off for good on October 1st.
@tgburgin Hey, yes absolutely. Coming with the other changes on sep 1st. It is long overdue.
ps. note that the servers have always served the root zones locally (almost since the start, long before RFC8806), so the real effect of QNAME minimization will not be as big. :)
Move went well, DNS server is operational after about 1 hour downtime.
Blog and other related services still down, ETA unknown, please be patient.
Have a nice day :)
Har jeg nogen venner hos SAC-IT?
De har købt noget hosting af Telia, inklusive det rack og IP net hvor jeg har censurfridns unicast noden stående.
Spændende hvad der sker nu, har møde med dem på onsdag.
@AnonAndro @tykling Very recently moved to Libera, #uncensoreddns for English and #censurfridns for Danish. Have not updated website with new irc network yet.
@Tonytweet74 Sorry to hear that, we've all been there and it is no fun. Does it work now? I'm a bit hung up at work right now but will be looking closer into possible reasons tonight where I have to update some stuff anyway.
@AnonAndro @tykling Thanks for reaching out, I have not heard about that before, but it sounds weird. I'd love to debug it with you at some point, do you do IRC or some other chat thing?
@Tonytweet74 You could consider switching to DoT or DoH (use a stub in your network like stubby) they are not included in the ratelimit stuff since they run TCP so spoofing is not an issue. You get better privacy and security as an added bonus :)
@AnonAndro @tykling What/how is DoH breaking? DoT and DoH are not subject to anti DDOS stuff and should just work, so more details are needed to troubleshoot if you have problems. No general issues with the DNS servers, they are handling their usual load with no changes apart from usual noise
@AnonAndro @tykling Hello, yes the service is still running. Monitoring had not caught the cert on the blog expiring, I've taken steps to prevent it happening again. Due to some ratelimit stuff at LE it will take 1-2 days before it is fixed, unless I find time to workaround it.