Diese Woche war eine gute Woche. Dreimal de-amerikanisiert mit
iCloud Mails —> #mailboxorg
Cloudflare DNS —> #deSEC
iCloud Drive —> #opencloud
Noch einige Aufräumarbeiten zu machen und einen Blogpost zu schreiben, speziell das docker compose für OpenCloud war schwieriger als es sein sollte.
• Moteur de Recherche : Google → @duckduckgo
Recherche anonymisée, sans pub.
• Filtrage DNS Réseau : DNS FAI → #NextDNS
Blocage des traqueurs, malwares et publicités à la source pour tous les appareils du réseau.
• Création nom de domaine : #deSEC
Accéder plus facilement à mes services.
3/13

HI there, I’m trying to install a chatmail server using deSEC as the DNS manager. However, the installer reports an error when running dig @get.desec.io. -r -q <my_domain> -t A +short. And if I run this same command from my command line I get the following error: ;; communications error to 2a01:4f8:10a:1044:deec:642:ac10:80#53: connection refused ;; communications error to 2a01:4f8:10a:1044:deec:642:ac10:80#53: connection refused ;; communications error to 2a01:4f8:10a:1044:deec:642:ac10:80#53...
#DNS question:
Is the "primary master name server" (MNAME) from a SOA entry required to answer DNS queries for the domain in question?
Asking, because desec.io does return "get.desec.io" as the primiary master name server for domains hosted at desec.io. But there is no DNS server answering requests under that domain.
#followerpower #desec #SOA #MNAME
@hbauer @mnord yes, called DNS-01 challenge https://letsencrypt.org/docs/challenge-types/#dns-01-challenge we use #desec.io as DNS provider.
At our home lab the #traefik http proxy handle those #letsencrypt and ssl encryption stuff and secure all the https traffic from the other containers automagically. It looks like nextcloud.home.domain.tld of course, you also need an internal DNS server for that. But that's anyway good as you have DNS blocker...

When you get a certificate from Let’s Encrypt, our servers validate that you control the domain names in that certificate using “challenges,” as defined by the ACME standard. Most of the time, this validation is handled automatically by your ACME client, but if you need to make some more complex configuration decisions, it’s useful to know more about them. If you’re unsure, go with your client’s defaults or with HTTP-01.
Kann es sein, dass ein mit deSEC eingerichteter DynDNS-Zugang öfter am Tag nicht verfügbar ist?
In letzter Zeit habe ich da häufiger Probleme mit der Erreichbarkeit. Das restliche Netzwerk und auch der Internetzugriff funktionieren ohne Probleme.
Hinter dem dynDNS hängt eine NextBox von NitroKey.