From owner-freebsd-stable@freebsd.org Mon Jun 6 13:33:20 2016 Return-Path: Delivered-To: freebsd-stable@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 18DF3B6B4D9 for ; Mon, 6 Jun 2016 13:33:20 +0000 (UTC) (envelope-from freebsd-stable-local@be-well.ilk.org) Received: from mailman.ysv.freebsd.org (mailman.ysv.freebsd.org [IPv6:2001:1900:2254:206a::50:5]) by mx1.freebsd.org (Postfix) with ESMTP id 075A01E2A for ; Mon, 6 Jun 2016 13:33:20 +0000 (UTC) (envelope-from freebsd-stable-local@be-well.ilk.org) Received: by mailman.ysv.freebsd.org (Postfix) id 06ACDB6B4D8; Mon, 6 Jun 2016 13:33:20 +0000 (UTC) Delivered-To: stable@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 0657AB6B4D7 for ; Mon, 6 Jun 2016 13:33:20 +0000 (UTC) (envelope-from freebsd-stable-local@be-well.ilk.org) Received: from be-well.ilk.org (be-well.ilk.org [23.30.133.173]) by mx1.freebsd.org (Postfix) with ESMTP id D94DA1E29 for ; Mon, 6 Jun 2016 13:33:19 +0000 (UTC) (envelope-from freebsd-stable-local@be-well.ilk.org) Received: from lowell-desk.lan (router.lan [172.30.250.2]) by be-well.ilk.org (Postfix) with ESMTP id 4E3CB33C22; Mon, 6 Jun 2016 09:33:03 -0400 (EDT) Received: by lowell-desk.lan (Postfix, from userid 1147) id F315239828; Mon, 6 Jun 2016 09:33:02 -0400 (EDT) From: Lowell Gilbert To: Slawa Olhovchenkov To: stable@freebsd.org Subject: Re: unbound and ntp issuse References: <20160602122727.GB75625@zxy.spb.ru> <44lh2mi0k5.fsf@lowell-desk.lan> <20160603191523.GE75630@zxy.spb.ru> Reply-To: stable@freebsd.org Date: Mon, 06 Jun 2016 09:33:02 -0400 In-Reply-To: <20160603191523.GE75630@zxy.spb.ru> (Slawa Olhovchenkov's message of "Fri, 3 Jun 2016 22:15:24 +0300") Message-ID: <44y46ie92p.fsf@lowell-desk.lan> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.5 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 06 Jun 2016 13:33:20 -0000 Slawa Olhovchenkov writes: > On Fri, Jun 03, 2016 at 02:34:18PM -0400, Lowell Gilbert wrote: > >> Slawa Olhovchenkov writes: >> >> > Default install with local_unbound and ntpd can't be functional with >> > incorrect date/time in BIOS: >> > >> > Unbound requred correct time for DNSSEC check and refuseing queries >> > ("Jul 1 20:17:29 yellowrat unbound: [3444:0] info: failed to prime >> > trust anchor -- DNSKEY rrset is not secure . DNSKEY IN") >> > >> > ntpd don't have any numeric IP of ntp servers in ntp.conf -- only >> > symbolic names like 0.freebsd.pool.ntp.org, as result -- can't >> > resolve (see above, about DNSKEY). >> >> I can't see how this would happen. DNSSEC doesn't seem to be required in >> a regular install as far as I can see. Certainly I don't have any > > I don't know reasson for enforcing DNSSEC in regular install. > I am just select `local_unbound` at setup time and enter `127.0.0.1` as > nameserver address. That's not enough to configure unbound as a fully recursive DNS server. If your system gets its address through DHCP, it is probably getting DNS server addresses as well, and would work fine *without* your configuring any of the DNS state. >> problem on any of my systems, and I've never configured an anchor on the >> internal systems. >> >> > IMHO, ntp.conf need to include some numeric IP of public ntp servers. >> >> Ouch; that's a terrible idea, for several different reasons. > > What else? All the normal reasons that hard-coding IP addresses is a bad idea; they can change, you're encouraging a lot of people to use the same ones, etc.