Date: Sat, 23 Jan 2016 20:18:09 -0500 From: Jon Radel <jon@radel.com> To: Aleksandr Miroslav <alexmiroslav@gmail.com>, freebsd-questions@freebsd.org Subject: Re: IPV6-ifying all my boxes -- any gotchas to be aware of? Message-ID: <56A42651.8050801@radel.com> In-Reply-To: <CACcSE1zTxziM-np_G41wk=MfodoGaT6qQ2bS5K3JxYSZFepYHA@mail.gmail.com> References: <CACcSE1zTxziM-np_G41wk=MfodoGaT6qQ2bS5K3JxYSZFepYHA@mail.gmail.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --]
On 1/23/16 7:38 PM, Aleksandr Miroslav wrote:
>
> Apart from some websites and mailing lists, I'm not running anything
> mission-critical, but I'd like to avoid snafus if possible. Are there any
> gotchas that I should be aware of?
>
Make sure that any firewalling you find prudent with ipv4 is replicated
as appropriate with ipv6 and double check what processes are actually
listening on ipv6. There's no good that will come of finding at a later
time that something, say a back-end database, is listening on ipv4
loopback address only, but is listening on the public ipv6 address with
no firewall blocking access. That would probably mean certain
assumptions about the security of your database are no longer true.
Make sure services actually work over ipv6 before putting AAAA records
in your DNS. Remember that there are an awful lot of client machines
out there that will prefer HTTP and SMTP over ipv6 once you have AAAA
records, but there are probably still some poor souls for whom this will
break connectivity or performance reaching your servers. (Though I'd
argue that this far into ipv6 roll-out that that's their, not your,
problem. However, if you have contracts with them or make money off of
them it would probably be your problem too.)
Consider putting a DNS resolver reachable over IPv6 in your resolv.conf
after appropriate testing, though this isn't necessary to make things work.
On the whole I've found the process pretty painless. (Well other than
that my business class provider at home STILL doesn't provide native
ipv6. Shame on you Cox Business.)
--Jon Radel
jon@radel.com
[-- Attachment #2 --]
0 *H
010
`He 0 *H
00 #SanzTgk!0
*H
0o10 USE10U
AddTrust AB1&0$UAddTrust External TTP Network1"0 UAddTrust External CA Root0
141222000000Z
200530104838Z010 UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CA0"0
*H
0
zSNpRV&IQZI`zQBy"aNv#
J n=ٺ.CRC|2PȦOZϓ%{0dV*$3DiFK3@@:*S= a<UNv%!)|qvO_T{5R"=,0-1YR73i-C֥wgQ'뼥8v8ߌIs:2:=F:WtaP@?⟢! 00U#0z4&&T$T0UakᢠOg£ 0U0U0 0U%0++0U
00U 0DU=0;09753http://crl.usertrust.com/AddTrustExternalCARoot.crl05+)0'0%+0http://ocsp.usertrust.com0
*H
*nU:Uka+ #fjow^a } [jr
AX&MX"cR6}Xޫ;cs{B#ʶM>K-ػBKiۦ74{:ǟO4ne6d)5ֱqC>2Svʆ4,Jؙ
␒ZBj#!eջ~ꌅ b:,Yř38zyJ&|00sT<}k
`i
0
*H
010 UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CA0
150330000000Z
180329235959Z010 UUS10U2215010 UVA10USpringfield10U 6917 Ridgeway Dr.10U
Jon T. Radel1200U)Issued through Jon T. Radel E-PKI Manager10UCorporate Secure Email10U Jon Radel10 *H
jon@radel.com0"0
*H
0
aЩ@@g3eGރ͛; d#>q7&Hf
:3vL"jV#Xݷ>U-H[$SUڻ{Ϝ,z¶IchO=rcyrn v.Vh7k;%ueYuӬnz6!| !Aȡ+,u+
CAպF-un#vjUJWnk%j]
2JPkl 00U#0akᢠOg£ 0UE|GDp/ʚB0U0U0 0U%0++0FU ?0=0;+10+0)+https://secure.comodo.net/CPS0]UV0T0RPNLhttp://crl.comodoca.com/COMODOSHA256ClientAuthenticationandSecureEmailCA.crl0+00X+0Lhttp://crt.comodoca.com/COMODOSHA256ClientAuthenticationandSecureEmailCA.crt0$+0http://ocsp.comodoca.com0U0
jon@radel.com0
*H
KS `?H_D`8G߿VbĘ<tB-Ӈї|{'Ũݹg0Gp$%F(;*MO*gt$@ t6,?0|#ăz,&! {j2i[%b7ߪP+9G㲍["y<?8rZ'[UR6%L̤
w"=:L~Ƨ^jf36 OP1.}(e1A0=0010 UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k
`i
0
`He a0 *H
1 *H
0 *H
1
160124011810Z0/ *H
1" -3\NrBytE|{
K<Hߔ0l *H
1_0]0 `He*0 `He0
*H
0*H
0
*H
@0+0
*H
(0 +710010 UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k
`i
0*H
1010 UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k
`i
0
*H
,M`Ā$;Js[!#03e(Yy93B4[ָA
a0EhrE&^Rޢ#j$,4Z;'l5ʰdqU]Iʭ,?+QuCc6-qsH!3` Wl8Y(կ||/̡Dz[x+<ȁ{O+lV{fĴl'oH3[SD:/ܳ% P`J.Z
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?56A42651.8050801>
