Unbound läuft
pi@raspberrypi:~ $ sudo systemctl status unbound.service● unbound.service - Unbound DNS server Loaded: loaded (/lib/systemd/system/unbound.service; enabled; vendor preset: enabled) Active: active (running) since Wed 2023-01-25 21:33:27 CET; 14min ago Docs: man:unbound(8) Process: 1059 ExecStartPre=/usr/lib/unbound/package-helper chroot_setup (code=exited, status=0/SUCCESS) Process: 1062 ExecStartPre=/usr/lib/unbound/package-helper root_trust_anchor_update (code=exited, status=0/SUCCESS) Main PID: 1065 (unbound) Tasks: 1 (limit: 4164) CPU: 1.126s CGroup: /system.slice/unbound.service └─1065 /usr/sbin/unbound -d -pJan 25 21:33:26 raspberrypi systemd[1]: Starting Unbound DNS server...Jan 25 21:33:27 raspberrypi unbound[1065]: [1065:0] info: start of service (unbound 1.13.1).Jan 25 21:33:27 raspberrypi systemd[1]: Started Unbound DNS server.
pi@raspberrypi:~ $ sudo dig creativeturtle.de @127.0.0.1 -p 5335; <<>> DiG 9.16.33-Debian <<>> creativeturtle.de @127.0.0.1 -p 5335;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 18514;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1472;; QUESTION SECTION:;creativeturtle.de. IN A;; Query time: 3143 msec;; SERVER: 127.0.0.1#5335(127.0.0.1);; WHEN: Wed Jan 25 21:51:49 CET 2023;; MSG SIZE rcvd: 46
Der sigfail-Test funktioniert auch
i@raspberrypi:~ $ sudo dig sigfail.verteiltesysteme.net @127.0.0.1 -p 5335; <<>> DiG 9.16.33-Debian <<>> sigfail.verteiltesysteme.net @127.0.0.1 -p 5335;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 59691;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1472;; QUESTION SECTION:;sigfail.verteiltesysteme.net. IN A;; Query time: 15 msec;; SERVER: 127.0.0.1#5335(127.0.0.1);; WHEN: Wed Jan 25 22:08:55 CET 2023;; MSG SIZE rcvd: 57
Der sigok-Test zeigt aber auch "SERVFAIL" an
pi@raspberrypi:~ $ sudo dig sigok.verteiltesysteme.net @127.0.0.1 -p 5335; <<>> DiG 9.16.33-Debian <<>> sigok.verteiltesysteme.net @127.0.0.1 -p 5335;; global options: +cmd;; Got answer:;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 61934;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1;; OPT PSEUDOSECTION:; EDNS: version: 0, flags:; udp: 1472;; QUESTION SECTION:;sigok.verteiltesysteme.net. IN A;; Query time: 15 msec;; SERVER: 127.0.0.1#5335(127.0.0.1);; WHEN: Wed Jan 25 22:10:05 CET 2023;; MSG SIZE rcvd: 55