From owner-freebsd-stable@freebsd.org Mon Jun 6 14:15:30 2016 Return-Path: Delivered-To: freebsd-stable@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id C2540B6D187 for ; Mon, 6 Jun 2016 14:15:30 +0000 (UTC) (envelope-from slw@zxy.spb.ru) Received: from mailman.ysv.freebsd.org (mailman.ysv.freebsd.org [IPv6:2001:1900:2254:206a::50:5]) by mx1.freebsd.org (Postfix) with ESMTP id B0EF218DF for ; Mon, 6 Jun 2016 14:15:30 +0000 (UTC) (envelope-from slw@zxy.spb.ru) Received: by mailman.ysv.freebsd.org (Postfix) id B02F2B6D186; Mon, 6 Jun 2016 14:15:30 +0000 (UTC) Delivered-To: stable@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id AFD0BB6D184 for ; Mon, 6 Jun 2016 14:15:30 +0000 (UTC) (envelope-from slw@zxy.spb.ru) Received: from zxy.spb.ru (zxy.spb.ru [195.70.199.98]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 7343518DE for ; Mon, 6 Jun 2016 14:15:30 +0000 (UTC) (envelope-from slw@zxy.spb.ru) Received: from slw by zxy.spb.ru with local (Exim 4.86 (FreeBSD)) (envelope-from ) id 1b9uv4-000PkJ-I8 for stable@freebsd.org; Mon, 06 Jun 2016 16:50:18 +0300 Date: Mon, 6 Jun 2016 16:50:18 +0300 From: Slawa Olhovchenkov To: stable@freebsd.org Subject: Re: unbound and ntp issuse Message-ID: <20160606135018.GL75630@zxy.spb.ru> References: <20160602122727.GB75625@zxy.spb.ru> <44lh2mi0k5.fsf@lowell-desk.lan> <20160603191523.GE75630@zxy.spb.ru> <44y46ie92p.fsf@lowell-desk.lan> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <44y46ie92p.fsf@lowell-desk.lan> User-Agent: Mutt/1.5.24 (2015-08-30) X-SA-Exim-Connect-IP: X-SA-Exim-Mail-From: slw@zxy.spb.ru X-SA-Exim-Scanned: No (on zxy.spb.ru); SAEximRunCond expanded to false X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 06 Jun 2016 14:15:30 -0000 On Mon, Jun 06, 2016 at 09:33:02AM -0400, Lowell Gilbert wrote: > Slawa Olhovchenkov writes: > > > On Fri, Jun 03, 2016 at 02:34:18PM -0400, Lowell Gilbert wrote: > > > >> Slawa Olhovchenkov writes: > >> > >> > Default install with local_unbound and ntpd can't be functional with > >> > incorrect date/time in BIOS: > >> > > >> > Unbound requred correct time for DNSSEC check and refuseing queries > >> > ("Jul 1 20:17:29 yellowrat unbound: [3444:0] info: failed to prime > >> > trust anchor -- DNSKEY rrset is not secure . DNSKEY IN") > >> > > >> > ntpd don't have any numeric IP of ntp servers in ntp.conf -- only > >> > symbolic names like 0.freebsd.pool.ntp.org, as result -- can't > >> > resolve (see above, about DNSKEY). > >> > >> I can't see how this would happen. DNSSEC doesn't seem to be required in > >> a regular install as far as I can see. Certainly I don't have any > > > > I don't know reasson for enforcing DNSSEC in regular install. > > I am just select `local_unbound` at setup time and enter `127.0.0.1` as > > nameserver address. > > That's not enough to configure unbound as a fully recursive DNS > server. What I am missing? Need to fix unbound setup scripts? bsdinstall scripts? As I see unbound setup scripts detects 127.0.0.1 in resolv.conf and configured unbound as fully recursive DNS server. > If your system gets its address through DHCP, it is probably > getting DNS server addresses as well, and would work fine *without* your > configuring any of the DNS state. I am have static address and don't getting DNS server address. > >> problem on any of my systems, and I've never configured an anchor on the > >> internal systems. > >> > >> > IMHO, ntp.conf need to include some numeric IP of public ntp servers. > >> > >> Ouch; that's a terrible idea, for several different reasons. > > > > What else? > > All the normal reasons that hard-coding IP addresses is a bad idea; they > can change, you're encouraging a lot of people to use the same ones, etc. And how to resolve this issuse: - default install with unbound as recursive DNS server (by default enforcing DNSSEC) - ntp time synchronisation - stale CMOS time (2008 year)