New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
running tinc via systemd does not seem to able to use dns #14433
Comments
cc @globin |
@fpletz will look at this later |
Hmm, I can't reproduce this here. Name resolution works for me within tinc. Also using tinc_pre in the same version. Have you checked that name resolution works in general on that host? |
Yes name resolution is fine on the host, and works fine when i call the tinc scripts as root. |
so I figured out what caused this issue, in upgrade chroot=true; is now the default. Setting my chroot=false; resolves the issue. Does anyone have a method for pulling in the resolv.conf in the chroot? Or do people get around this issue by just not using dns? |
Huh, can you back this off with some link(s)? |
so before there was no chroot flag being passed, so tincs default was to set it false. now the service is passing it and setting it to true by default. which is fine it adds more security just a change from 15.07 to 16.03, and at least currently im not sure how to enable this feature and still get dns correctly into the chroot. |
triton/triton@da08fa6
|
that looks like a good fix if chroot is enabled we should do that |
i tested chroot on my box and it seems to be resolving dns correctly now. |
I can confirm that even with today's version - 19.03, I need to set |
See also #66432. |
Issue description
Before I upgraded to 16.03 I had a tinc use dns to find the vpn host it connects to. Since upgrading to 16.03 it no longer seems to be able to use dns. if I change the dns name to a static ip my problem of connecting to the vpn goes away.
Steps to reproduce
Setup a tinc environment using hostnames and not static ips
Technical details
16.03.498.f8a5d1e (Emu)
nix-env (Nix) 1.11.2
"16.03.498.f8a5d1e"
journalctl output
The text was updated successfully, but these errors were encountered: