Settings

Theme

Unwind: A privilege-separated DNS recursive nameserver for every laptop [pdf]

openbsd.org

76 points by Jonhoo 7 years ago · 6 comments

Reader

ahazred8ta 7 years ago

https://man.openbsd.org/unwind.8 uses libunbound; it detects whether local DHCP DNS is working, works correctly with captive portals, and supports opportunistic or strict DNSSEC.

This was discussed in https://news.ycombinator.com/item?id=19738313 in April

eikenberry 7 years ago

Is it basically just a stripped down version of Unbound or does it provide any additional functionality?

  • eikenberry 7 years ago

    The blog post gives some hints at what it does differently but makes odd claims about unbound not working with captive portals, which I've never had any problems with. But maybe I've just been on well behaved networks or something. Look forward to this being done and ported.

    • marios 7 years ago

      It depends how your unbound is configured. In my case, I have unbound running on my laptop configured as a recursive resolver; i.e: it will not query the DHCP provided DNS.

      In networks with captive portals, the DHCP provided DNS will have a record for a URL where the user has to enter credentials or at the very least agree to the terms and conditions. Very often though, that URL only resolves locally, so in my setup the captive portal setup doesn't work seamlessly.

equalunique 7 years ago

Mental note: Find the talk where these slides were presented.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection