<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=7717&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Fail With DOT]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=7717</link>
		<description><![CDATA[The most recent posts in Fail With DOT.]]></description>
		<lastBuildDate>Sat, 07 Mar 2026 02:45:11 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Fail With DOT]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=62585#p62585</link>
			<description><![CDATA[<div class="quotebox"><cite>ralph.ronnquist wrote:</cite><blockquote><div><p>what is PFS</p></div></blockquote></div><div class="quotebox"><cite>man wget wrote:</cite><blockquote><div><p>&#160; &#160; &#160; &#160;--secure-protocol=protocol<br />&#160; &#160; &#160; &#160; &#160; &#160;Choose the secure protocol to be used.&#160; Legal values are auto,<br />&#160; &#160; &#160; &#160; &#160; &#160;SSLv2, SSLv3, TLSv1, TLSv1_1, TLSv1_2, TLSv1_3 and PFS.&#160; If<br />&#160; &#160; &#160; &#160; &#160; &#160;auto is used, the SSL library is given the liberty of choosing<br />&#160; &#160; &#160; &#160; &#160; &#160;the appropriate protocol automatically, which is achieved by<br />&#160; &#160; &#160; &#160; &#160; &#160;sending a TLSv1 greeting. This is the default.</p><p>&#160; &#160; &#160; &#160; &#160; &#160;Specifying SSLv2, SSLv3, TLSv1, TLSv1_1, TLSv1_2 or TLSv1_3<br />&#160; &#160; &#160; &#160; &#160; &#160;forces the use of the corresponding protocol.&#160; This is useful<br />&#160; &#160; &#160; &#160; &#160; &#160;when talking to old and buggy SSL server implementations that<br />&#160; &#160; &#160; &#160; &#160; &#160;make it hard for the underlying SSL library to choose the<br />&#160; &#160; &#160; &#160; &#160; &#160;correct protocol version.&#160; Fortunately, such servers are quite<br />&#160; &#160; &#160; &#160; &#160; &#160;rare.</p><p>&#160; &#160; &#160; &#160; &#160; &#160;Specifying PFS enforces the use of the so-called Perfect<br />&#160; &#160; &#160; &#160; &#160; &#160;Forward Security cipher suites. In short, PFS adds security by<br />&#160; &#160; &#160; &#160; &#160; &#160;creating a one-time key for each SSL connection. It has a bit<br />&#160; &#160; &#160; &#160; &#160; &#160;more CPU impact on client and server.&#160; We use known to be<br />&#160; &#160; &#160; &#160; &#160; &#160;secure ciphers (e.g. no MD4) and the TLS protocol. This mode<br />&#160; &#160; &#160; &#160; &#160; &#160;also explicitly excludes non-PFS key exchange methods, such as<br />&#160; &#160; &#160; &#160; &#160; &#160;RSA.</p></div></blockquote></div><p>i.e. more paranoia BS, from someone with likely little idea what it actually does or what attacks it might defend against, since they apparently need &quot;step by step&quot; instructions to write a trivial init script.</p><p>Next will be out-of-repo &quot;privacy&quot; browsers, VPNs, and whatever go-fast shiny-new-shit is popular on Arch/Artix right now.</p><div class="quotebox"><cite>onedevone wrote:</cite><blockquote><div><p>Toxic answeres.</p></div></blockquote></div><p>&quot;Toxic&quot; OP, complete with entitlement, shouting, and misguided assertions that <em>your personal preference</em> regarding DNS should be a distro-wide default.</p><div class="quotebox"><cite>onedevone wrote:</cite><blockquote><div><p>DOT is not something to be laughed at</p></div></blockquote></div><p>I&#039;m not laughing at DoT, I&#039;m laughing at people who consider it not being enabled by default and integrated into some random GUI a &quot;complete showstopper&quot;.<br />Devuan, like Debian, comes with a <em>standard</em> DNS configuration by default. If you want something else, it&#039;s on you to read the documentation and set it up.<br />Likewise init systems - sysv is the default and best supported. If you want something else, all the parts are available but <em>you</em> get to assemble them.</p>]]></description>
			<author><![CDATA[dummy@example.com (steve_v)]]></author>
			<pubDate>Sat, 07 Mar 2026 02:45:11 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=62585#p62585</guid>
		</item>
		<item>
			<title><![CDATA[Re: Fail With DOT]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=62575#p62575</link>
			<description><![CDATA[<p>what is PFS now? Is language too hard to be written in full?</p>]]></description>
			<author><![CDATA[dummy@example.com (ralph.ronnquist)]]></author>
			<pubDate>Fri, 06 Mar 2026 08:48:20 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=62575#p62575</guid>
		</item>
		<item>
			<title><![CDATA[Re: Fail With DOT]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=62571#p62571</link>
			<description><![CDATA[<p>Toxic answeres. DOT is not something to be laughed at as is not my alias for wget with PFS for using it among others with Devuan servers.</p>]]></description>
			<author><![CDATA[dummy@example.com (onedevone)]]></author>
			<pubDate>Fri, 06 Mar 2026 08:40:01 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=62571#p62571</guid>
		</item>
		<item>
			<title><![CDATA[Re: Fail With DOT]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=61126#p61126</link>
			<description><![CDATA[<p>The initscript for stubby didn&#039;t make it in before the Debian Trixie freeze: <a href="https://tracker.debian.org/news/1650899/accepted-getdns-173-1-source-into-experimental/" rel="nofollow">https://tracker.debian.org/news/1650899 … erimental/</a></p><p>If anyone wants the current version in Excalibur it might be worth politely indicating on the Debian BTS that there would be demand for a stable backport.</p>]]></description>
			<author><![CDATA[dummy@example.com (abower)]]></author>
			<pubDate>Mon, 05 Jan 2026 17:45:56 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=61126#p61126</guid>
		</item>
		<item>
			<title><![CDATA[Re: Fail With DOT]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=61049#p61049</link>
			<description><![CDATA[<div class="quotebox"><blockquote><div><p>a somewhat less retarded attempt to break the &#039;net than DoH, from the usual paranoia crowd who think moving trust from their ISP to some other random entity (usually Google or Cloudflare) is progress</p></div></blockquote></div><p><a href="https://en.wikipedia.org/wiki/DNS_over_HTTPS" rel="nofollow">https://en.wikipedia.org/wiki/DNS_over_HTTPS</a></p><p>@steve_v&#160; &#160;Wow two times in one week you have put a smile on my old face. Thank you!</p><p>TC</p>]]></description>
			<author><![CDATA[dummy@example.com (trinidad)]]></author>
			<pubDate>Fri, 02 Jan 2026 16:43:33 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=61049#p61049</guid>
		</item>
		<item>
			<title><![CDATA[Re: Fail With DOT]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=61037#p61037</link>
			<description><![CDATA[<p>OP reads like some AI slopper someone is posting for shits and giggles from 4chan.</p>]]></description>
			<author><![CDATA[dummy@example.com (HardSun)]]></author>
			<pubDate>Fri, 02 Jan 2026 06:21:16 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=61037#p61037</guid>
		</item>
		<item>
			<title><![CDATA[Re: Fail With DOT]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=61035#p61035</link>
			<description><![CDATA[<div class="quotebox"><cite>ralph.ronnquist wrote:</cite><blockquote><div><p>What is DOT ?</p></div></blockquote></div><p>DNS over TLS, AKA a somewhat less retarded attempt to break the &#039;net than DoH, from the usual paranoia crowd who think moving trust from their ISP to some other random entity (usually Google or Cloudflare) is progress.</p><div class="quotebox"><cite>onedevone wrote:</cite><blockquote><div><p>you wouldn&#039;t allow plain text DNS querries, would you?</p></div></blockquote></div><p>DNS is handled on my router, because I have a brain.</p><div class="quotebox"><cite>onedevone wrote:</cite><blockquote><div><p>I don&#039;t understand this behavior of nm</p></div></blockquote></div><p>Then you should probably ask RedHat, Devuan didn&#039;t write NetworkMangler.</p><div class="quotebox"><cite>onedevone wrote:</cite><blockquote><div><p>I looked for &quot;stubby-openrc&quot; but cannot find it.</p></div></blockquote></div><p>What makes you think someone else should write your init scripts for you? <br />The stubby package comes with a sysvinit script, because that&#039;s the default init. OpenRC is supported, but you don&#039;t get everything handed to you on a silver platter.<br />If you want an openrc init script, swiping it from Artix will probably work without too much modification. Otherwise, writing your own isn&#039;t complicated.</p><div class="quotebox"><cite>onedevone wrote:</cite><blockquote><div><p>THIS IS A COMPLETE SHOWSTOPPER FOR ME.</p></div></blockquote></div><p>Huh, what a coincidence. Shouting is a complete showstopper for me providing any kind of <del>spoon feeding</del> step-by-step instructions.</p><div class="quotebox"><cite>onedevone wrote:</cite><blockquote><div><p>Your help is going to be immensly appreciated.</p></div></blockquote></div><p>With the entitled and confrontational attitude you&#039;ve displayed in all your posts so far, I&#039;ll be surprised if you get much of that.</p>]]></description>
			<author><![CDATA[dummy@example.com (steve_v)]]></author>
			<pubDate>Fri, 02 Jan 2026 05:48:01 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=61035#p61035</guid>
		</item>
		<item>
			<title><![CDATA[Re: Fail With DOT]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=61034#p61034</link>
			<description><![CDATA[<p>What is DOT ?</p>]]></description>
			<author><![CDATA[dummy@example.com (ralph.ronnquist)]]></author>
			<pubDate>Fri, 02 Jan 2026 04:22:54 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=61034#p61034</guid>
		</item>
		<item>
			<title><![CDATA[Fail With DOT]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=61004#p61004</link>
			<description><![CDATA[<p>For years I have been managing Artix, but I had never had a success on Devuan 5. Nor do I know how to set up network on Devuan.</p><p>What is happening:</p><p>1. I put DOT capable IPs in KDEs network manager GUI. Testing shows, that not DOT is used. Plain queries <img src="https://dev1galaxy.org/img/smilies/sad.png" width="15" height="15" alt="sad" />((. It should be default, but isn&#039;t. It&#039;s been buffling me for years that you don&#039;t do this by default. This bears the question if you use your own creationa at all. If you were then you wouldn&#039;t allow plain text DNS querries, would you? I don&#039;t understand this behavior of nm.</p><p>2. I looked for &quot;stubby-openrc&quot; but cannot find it. I also theoreticaly could &quot;cap_net_bind blah blah&quot; reprogramm it (systemd has stubby working out of the box!). But I&#039;m stuck and I don&#039;t want to dwell on it.</p><p>HOW do you (step by step) do stubby on open-rc Devuan 6? THIS IS A COMPLETE SHOWSTOPPER FOR ME. I cannot continue the setup until I have this issue resolved.</p><p>DOT via stubby works like charm on Artix runit.</p><p>How do you do this on Devuan 6 Opne-RC? Your help is going to be immensly appreciated.</p><p>Thanks.</p>]]></description>
			<author><![CDATA[dummy@example.com (onedevone)]]></author>
			<pubDate>Thu, 01 Jan 2026 12:45:39 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=61004#p61004</guid>
		</item>
	</channel>
</rss>
