3 ms·
That I did not know it had happened, as it was a silent change (and indeed, a change which survived uninstallation of the VPN). So in the end, when I stumbled
by Max-Ganz-II 4y ago
That I did not know it had happened, as it was a silent change (and indeed, a change which survived uninstallation of the VPN).
So in the end, when I stumbled across it, I did change it back - but I had a malformed DNS config for the months before, by chance, finding the change.
That I could change it back isn't much use when I had no idea the change had occurred.
- viraptor 4y agoWith VPNs implementing split-horizon / internal DNS, all of them will change the resolver config. There's no way around it really without more hacky solutions. It definitely should revert the config on each disconnect, so maybe it's just a bug.
- vetinari 4y agoThere are pretty defined ways how to handle this, just communicate with NetworkManager, set up the DNS info on your link and it will do the right thing (any desktop machine from the last 10 years, which is going to have user-managed VPN is going to run NetworkManager); modifying resolv.conf is the hacky way.
- Max-Ganz-II 4y agoYes - this articulates my expectation of a VPN client. DNS should be modified when and only when it is running. That is not the case here.
- nix23 4y ago>That I did not know it had happened, as it was a silent change So no HIDS like Samhain or OSSEC in place?
- Max-Ganz-II 4y agoI'm not that strong a user, I'm afraid. Just an ordinary person, living in fear of VPN clients :-)
- nix23 4y agoNo problem try to make resolv.conf immutable with: chattr +i /etc/resolv.conf Not even root can then change it without removing the attribute (-i) However HIDS are really nice to detect stuff like that...and they are not that complicated (OSSEC or samhain)
- Max-Ganz-II 4y agoI'd actually not heard of HIDS before, so now I'm aware of them, I can look into them when there's a good moment to Google a bit. All part of that learning curve :-)