Replies: 1 comment
-
|
Looks like we have implemented option 2/ of https://www.rfc-editor.org/rfc/rfc7873#section-5.2.3. While it's a nice choice when the server is under attack, I'm not sure it makes sense to do that by default, because in effect it penalizes clients that support EDNS cookies which is quite the opposite of what we want. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi,
I'm trying to configure
edns-cookie-secreton a authoritative powerdns server.I am getting BADCOOKIE responses when testing with a dig. I am not sure if I am doing something wrong or misunderstanding something.
My configuration is:
/etc/powerdns/pdns.conf:dig response:
I think that the retry works, as it does show a COOKIE in the response - at least I am not seeing any error except that very first line, but it happens every single lookup and for all domains.
tcpdump:
I am using powerdns 5.0.1. Is there anything I can do to figure out what causes this?
Beta Was this translation helpful? Give feedback.
All reactions