Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.2.1 Force disabling of harden glue? Why?

    Scheduled Pinned Locked Moved DHCP and DNS
    7 Posts 4 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      Trel
      last edited by

      Force disabling of harden glue configuration option, and remove GUI control of that option. Problem with Unbound pre-1.5.2 means in 2.2-RELEASE, having this option enabled, and DNSSEC disabled, could lead to DNS cache poisoning.

      It references this bug: https://redmine.pfsense.org/issues/4402

      Why is this being force disabled?  That was the option to enable to stop the cache poisoning myself and many others were experiencing.
      It was having it OFF that led to the poisoning.

      1 Reply Last reply Reply Quote 0
      • D Offline
        doktornotor Banned
        last edited by

        Huh?! It is force-enabled.

        1 Reply Last reply Reply Quote 0
        • T Offline
          Trel
          last edited by

          @doktornotor:

          Huh?! It is force-enabled.

          That's not what it says here: https://doc.pfsense.org/index.php?title=2.2.1_New_Features_and_Changes#DNS_Resolver

          1 Reply Last reply Reply Quote 0
          • D Offline
            doktornotor Banned
            last edited by

            
            $ grep glue /var/unbound/unbound.conf
            harden-glue: yes
            
            $ cat /etc/version
            2.2.1-RELEASE
            
            

            https://github.com/pfsense/pfsense/commit/5c7c369f5f2c9584ad53a5657965deb2d6661da2

            1 Reply Last reply Reply Quote 0
            • T Offline
              Trel
              last edited by

              @doktornotor:

              
              $ grep glue /var/unbound/unbound.conf
              harden-glue: yes
              
              $ cat /etc/version
              2.2.1-RELEASE
              
              

              https://github.com/pfsense/pfsense/commit/5c7c369f5f2c9584ad53a5657965deb2d6661da2

              So it's the chagelog that's wrong, not the actual release then.  That's a relief.
              (I'm sure you know what I was looking so closely at that line heh, thanks again BTW for being able to test with those sites that were doing the poisoning)

              1 Reply Last reply Reply Quote 0
              • K Offline
                kejianshi
                last edited by

                seems to be about the size of things.  Typo.

                1 Reply Last reply Reply Quote 0
                • jimpJ Offline
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  I fixed the changelog (See also https://redmine.pfsense.org/issues/4402 )

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.