4 ms·
I had the power turned off at home about a year ago. I think it was due to maintenance by the utilities company, or maybe I did it for DIY reasons. Anyway, aft
by HaroldBolt78 3y ago
I had the power turned off at home about a year ago. I think it was due to maintenance by the utilities company, or maybe I did it for DIY reasons.
Anyway, after it came back on, it took me far too long to realise why my internet was down. All DNS responses were being rejected. It turns out, my Pi-Hole DNS server - which had forgotten the time, of course - was trying to resolve the IP of an NTP server so it could fetch the current time, but this name resolution was over DNSSEC which requires the current time. You need the time to get the time.
I turned off DNSSEC and haven't looked back since.
- bouke 3y agoI had exactly the same issue happening to me! I’ve since added a Real Time Clock (RTC), so the Pi shouldn’t forget about the current time anymore. That is until the battery runs out of course, for which there is no monitoring in place. So yeah maybe I should disable DNSSEC as well. At least we need to get better at building fault tolerant systems. Maybe Pi-Hole needs to be aware of and handle this scenario better: a special “we’re booting up and we don’t have the current time so don’t do DNSSEC yet”.
- toast0 3y agofake-hwclock[1] is useful for this. I don't know much about Pi-Hole, but if it involves writable storage and has a package manager, fake-hwclock may be available from there. > At least we need to get better at building fault tolerant systems. Security and fault tolerance are at odds here. Failing closed when you can't validate is correct, but not so useful. Properly modeling the clock might give you a way to get bootstrapped, but then an adversary would arrange for a bootstrap situation so they could interfere with your clock and then make use of the incorrect time for their nefarious purposes. [1] https://git.einval.com/cgi-bin/gitweb.cgi?p=fake-hwclock.git https://git.einval.com/cgi-bin/gitweb.cgi?p=fake-hwclock.git
- boringuser2 3y agoDoes pihole even have value anymore with DNS over https? I'd just implement that in 0.2 nanoseconds if I were a Samsung engineer making an intrusive adserver.
- elcomet 3y agoWhat's your alternative to the pihole with dns over https?
- Am4TIfIsER0ppos 3y agoGrandparent is saying that DoH ignores the dns settings on your computer and on your network (from dhcp) because every piece of software and every "smart" device just asks cloudflare where to go meaning pihole is ineffective.
- toast0 3y agoWouldn't you just have your pihole block well known resolver ips and solve that problem?
- citrin_ru 3y agoFor me it's a reason to use IP address in /etc/ntp.conf instead. DNS over HTTPS and HTTPS in general also need current time to validate a certificate so DNSSEC is not unique here.
- Avamander 3y agoThis makes Network Time Security difficult. This is a reason you add an RTC to your RPi.