Environment & Version
Environment
Version
- Mailu Version:
2.0
- Docker Engine 24.0.0
Description
I upgraded today our mail server system to docker engine 24.0.0 and it broke DNSSEC with ubound resolver container
mailu-admin-1 | [2023-05-17 16:30:51,391] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:51,392] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:51,393] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:51,393] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:51,398] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:51,400] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:51,400] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:51,402] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:51,410] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:51,412] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:51,413] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:51,414] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:52,079] WARNING in utils: Unable to lookup the TLSA record for hotmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/hotmail.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:52,081] WARNING in utils: Unable to lookup the TLSA record for yahoo.com. Is the DNSSEC zone okay on https://dnsviz.net/d/yahoo.com/dnssec/?
mailu-admin-1 | [2023-05-17 16:30:52,085] WARNING in utils: Unable to lookup the TLSA record for yahoo.com. Is the DNSSEC zone okay on https://dnsviz.net/d/yahoo.com/dnssec/?
i checked if i can ping the resolver container from the other services e.g. admin and smtp which worked and resolved
i checked if i can ping anything outside e.g. google from these containers which worked too
i checked if i can do all of this from the resolver container it self too .. working fine also
i checked if the dns for all the different containers is set, and admin as well as smtp had the resolver IP entered
I tried to add DNS servers to the resolver container which did not make a difference
i also stopped the resolver process to see if it is even used, and i got a host lookup issue in the smtp with that, so i knew it is used.
Temporary solution
I ultimately downgraded docker engine to the latest 23 release where everything started to work again.
apt install docker-ce=5:23.0.6-1~debian.11~bullseye
apt install docker-ce-cli=5:23.0.6-1~debian.11~bullseye
apt install docker-ce-rootless-extras=5:23.0.6-1~debian.11~bullseye
Replication Steps
upgrade docker engine to 24.0.0 on Debian via https://docs.docker.com/engine/install/debian/
Observed behaviour
DNSSEC lookup stops working.
Logs
syslog:May 17 15:39:11 mx01 mailu-admin[2315519]: [2023-05-17 15:39:11,884] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
syslog:May 17 15:39:11 mx01 mailu-smtp[2315519]: May 17 15:39:11 mx01 postfix/smtp[1693]: warning: TLS policy lookup for gmail.com/gmail-smtp-in.l.google.com: non DNSSEC destination
syslog:May 17 15:39:11 mx01 mailu-smtp[2315519]: May 17 15:39:11 mx01 postfix/smtp[1693]: warning: TLS policy lookup for gmail.com/gmail-smtp-in.l.google.com: non DNSSEC destination
syslog:May 17 15:39:11 mx01 mailu-admin[2315519]: [2023-05-17 15:39:11,888] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
syslog:May 17 15:39:11 mx01 mailu-smtp[2315519]: May 17 15:39:11 mx01 postfix/smtp[1693]: warning: TLS policy lookup for gmail.com/alt1.gmail-smtp-in.l.google.com: non DNSSEC destination
syslog:May 17 15:39:11 mx01 mailu-smtp[2315519]: May 17 15:39:11 mx01 postfix/smtp[1693]: warning: TLS policy lookup for gmail.com/alt1.gmail-smtp-in.l.google.com: non DNSSEC destination
syslog:May 17 15:39:11 mx01 mailu-admin[2315519]: [2023-05-17 15:39:11,892] WARNING in utils: Unable to lookup the TLSA record for gmail.com. Is the DNSSEC zone okay on https://dnsviz.net/d/gmail.com/dnssec/?
syslog:May 17 15:39:11 mx01 mailu-smtp[2315519]: May 17 15:39:11 mx01 postfix/smtp[1693]: warning: TLS policy lookup for gmail.com/alt2.gmail-smtp-in.l.google.com: non DNSSEC destination
syslog:May 17 15:39:11 mx01 mailu-smtp[2315519]: May 17 15:39:11 mx01 postfix/smtp[1693]: D45F460087: to=<hidden-address@gmail.com>, relay=none, delay=506, delays=506/0.02/0.24/0, dsn=4.7.5, status=deferred (non DNSSEC destination)
Environment & Version
Environment
Version
2.0Description
I upgraded today our mail server system to docker engine 24.0.0 and it broke DNSSEC with ubound resolver container
i checked if i can ping the resolver container from the other services e.g. admin and smtp which worked and resolved
i checked if i can ping anything outside e.g. google from these containers which worked too
i checked if i can do all of this from the resolver container it self too .. working fine also
i checked if the dns for all the different containers is set, and admin as well as smtp had the resolver IP entered
I tried to add DNS servers to the resolver container which did not make a difference
i also stopped the resolver process to see if it is even used, and i got a host lookup issue in the smtp with that, so i knew it is used.
Temporary solution
I ultimately downgraded docker engine to the latest 23 release where everything started to work again.
Replication Steps
upgrade docker engine to 24.0.0 on Debian via https://docs.docker.com/engine/install/debian/
Observed behaviour
DNSSEC lookup stops working.
Logs