[tor-relays] Let's increase the amount of exit relays doing DNSSEC validation

Jonathan Sélea jonathan at selea.se
Sun Apr 15 19:09:02 UTC 2018


Great initiative!
Personally I would also see some sort of "DANE" for Tor-relays in the
future too, but that is a request for another thread.

/ Jonathan
> On 12.04.18 13:05, Alexander Dietrich wrote:
>
>> Just to be safe, you could also check the rest of the dig output and
>> /etc/resolv.conf (or relevant resolver configuration on your system)
>> to make sure your BIND is being used.
> I have seen hosters where /etc/resolv.conf is overwritten whenever the
> system reboots, and in these cases I used the following:
>
>   # Add this to /etc/tor/torrc
>   ServerDNSResolvConfFile /etc/tor/resolv.conf
>
>   # /etc/tor/resolv.conf
>   nameserver 127.0.0.1
>   # IPv6 alternative
>   #nameserver ::1
>
> -Ralph
>
> _______________________________________________
> tor-relays mailing list
> tor-relays at lists.torproject.org
> https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3968 bytes
Desc: S/MIME-kryptografisk signatur
URL: <http://lists.torproject.org/pipermail/tor-relays/attachments/20180415/4709cdcd/attachment-0001.bin>


More information about the tor-relays mailing list