Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 23 Jan 2016 20:18:09 -0500
From:      Jon Radel <jon@radel.com>
To:        Aleksandr Miroslav <alexmiroslav@gmail.com>, freebsd-questions@freebsd.org
Subject:   Re: IPV6-ifying all my boxes -- any gotchas to be aware of?
Message-ID:  <56A42651.8050801@radel.com>
In-Reply-To: <CACcSE1zTxziM-np_G41wk=MfodoGaT6qQ2bS5K3JxYSZFepYHA@mail.gmail.com>
References:  <CACcSE1zTxziM-np_G41wk=MfodoGaT6qQ2bS5K3JxYSZFepYHA@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
On 1/23/16 7:38 PM, Aleksandr Miroslav wrote:
>
> Apart from some websites and mailing lists, I'm not running anything
> mission-critical, but I'd like to avoid snafus if possible. Are there any
> gotchas that I should be aware of?
>
Make sure that any firewalling you find prudent with ipv4 is replicated 
as appropriate with ipv6 and double check what processes are actually 
listening on ipv6.  There's no good that will come of finding at a later 
time that something, say a back-end database, is listening on ipv4 
loopback address only, but is listening on the public ipv6 address with 
no firewall blocking access.  That would probably mean certain 
assumptions about the security of your database are no longer true.

Make sure services actually work over ipv6 before putting AAAA records 
in your DNS.  Remember that there are an awful lot of client machines 
out there that will prefer HTTP and SMTP over ipv6 once you have AAAA 
records, but there are probably still some poor souls for whom this will 
break connectivity or performance reaching your servers.  (Though I'd 
argue that this far into ipv6 roll-out that that's their, not your, 
problem.  However, if you have contracts with them or make money off of 
them it would probably be your problem too.)

Consider putting a DNS resolver reachable over IPv6 in your resolv.conf 
after appropriate testing, though this isn't necessary to make things work.

On the whole I've found the process pretty painless.  (Well other than 
that my business class provider at home STILL doesn't provide native 
ipv6.  Shame on you Cox Business.)

--Jon Radel
jon@radel.com






[-- Attachment #2 --]
0	*H
010
	`He0	*H

00#SanzTgk!0
	*H
0o10	USE10U
AddTrust AB1&0$UAddTrust External TTP Network1"0 UAddTrust External CA Root0
141222000000Z
200530104838Z010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CA0"0
	*H
0

zSNpRV&IQZI`zQBy"aNv#
J	n=ٺ.CRC|2PȦOZϓ%{0dV*$3DiFK3@@:*S= a<UNv%!)|qvO_T{5R"=,0-1YR73i-C֥wgQ'뼥8v8ߌIs:2:=F:WtaP@?⟢!00U#0z4&&T$T0UakᢠOg£0U0U00U%0++0U 
00U 0DU=0;09753http://crl.usertrust.com/AddTrustExternalCARoot.crl05+)0'0%+0http://ocsp.usertrust.com0
	*H
*nU:Uka+	#fjow^a}[jr
AX&MX"cR6}Xޫ;cs{B#ʶM>K-ػBKiۦ74{:ǟO4ne6d)5ֱqC>2Svʆ4,Jؙ
␒ZBj#!eջ~ꌅ b:,Yř38zyJ&|00sT<}k
`i
0
	*H
010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CA0
150330000000Z
180329235959Z010	UUS10U2215010	UVA10USpringfield10U	6917 Ridgeway Dr.10U
Jon T. Radel1200U)Issued through Jon T. Radel E-PKI Manager10UCorporate Secure Email10U	Jon Radel10	*H
	
jon@radel.com0"0
	*H
0
aЩ@@g3eGރ͛;	d#>q7&Hf
:3vL"jV#Xݷ>U-H[$SUڻ{Ϝ,z¶IchO=rcyrnv.Vh7k;%ueYuӬ󯅅nz6!| !Aȡ+,u+ 
CAպF-un#vjUJWnk%j]
2JPkl00U#0akᢠOg£0UE|GDp/ʚB0U0U00U%0++0FU ?0=0;+10+0)+https://secure.comodo.net/CPS0]UV0T0RPNLhttp://crl.comodoca.com/COMODOSHA256ClientAuthenticationandSecureEmailCA.crl0+00X+0Lhttp://crt.comodoca.com/COMODOSHA256ClientAuthenticationandSecureEmailCA.crt0$+0http://ocsp.comodoca.com0U0
jon@radel.com0
	*H
KS`?H_D`8G߿VbĘ<tB-Ӈї|{'Ũݹg0Gp$%F(;*MO*gt$@t6,?0|#ăz,&!{j2i[%b7ߪP+9G㲍["y<?8rZ'[UR6%L̤
w"=:L~Ƨ^jf36 OP1•.}(e1A0=0010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k
`i
0
	`Hea0	*H
	1	*H
0	*H
	1
160124011810Z0/	*H
	1" -3\NrBytE|{
K<Hߔ0l	*H
	1_0]0	`He*0	`He0
*H
0*H
0
*H
@0+0
*H
(0	+710010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k
`i
0*H
	1010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k
`i
0
	*H
,M`Ā$;Js[•!#03e(Yy93B4[ָA
a0EhrE&^Rޢ#j$,4Z;'l5ʰdqU]Iʭ,?+QuCc6-qsH!3` Wl8Y(կ||/̡Dz[x+<ȁ{O+lV{fĴl'oH3[SD:/ܳ%P`J.Z

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?56A42651.8050801>