[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: NetworkManager with dnsmasq caching NXDOMAIN response of router



> Note that .home is somewhat of a special snowflake with regards to
> TLDs. It was suggested as the default for HNCP in 2016 (RFC 7788
> section 8 <https://www.rfc-editor.org/rfc/rfc7788#section-8>);
> rejected as a gTLD in 2018
>
<https://www.icann.org/en/board-activities-and-meetings/materials/approved-board-resolutions-regular-meeting-of-the-icann-board-04-02-2018-en#2.c
>;
> and then the usage from RFC 7788 was effectively superceded by the
> recommendation and assignment for non-unique use of home.arpa a few
> months later in RFC 8375 <https://www.rfc-editor.org/rfc/rfc8375>.
> 
> This may or may not have anything to do with your issues; but in
> general, making up own TLDs and hoping that they will never conflict
> with public ones is a bad idea these days. Just look at how many
> internal names suddenly started having issues after Google was
> assigned .dev in 2019; to say nothing of that they made it a
> preloaded-HSTS TLD.
> 
> It's better to either use .home.arpa (which is specifically reserved
> for the purpose) or to actually register a domain (even if the name
> server delegations are bogus so it never meaningfully resolves on the
> public Internet).

Thank you for the insight!

I just clicked through the routers DHCP configuration options (note
there are no explicit DNS options).  This is a ZTS ZXHN H268N Router
provided with a custom Firmware A1 WLAN Box 027_42w2_MU from my
provider that claims "The firmware of your device is the latest."...

... and I haven't found a way to configure the domain.

But note, if I do _not_ configure 
/etc/NetworkManager/conf.d/localdns.conf
dns=dnsmasq

but leave the default, then DNS resolves fine.

It's only when I add dnsmasq to handle the .vpn and .virt domains that
the .home domain starts caching the NXDOMAIN responses and causes
issues.  So I'm still crossing my fingers that this can be resolved
with some dnsmasq configuration which I haven't understood yet.

Thanks!
David

PS: forgive me for repeating: it seems I'm not receiving mails via the
list subscription so please keep my CC:ed if you will.  Thank you!

-- 
David Ayers

Supporting:
Free Software Foundation Europe        []   (http://www.fsfe.org)
Become a supporter of the FSFE!      [][][] 
Your donation powers important work!   ||   (http://fsfe.org/donate)

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: