Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


SEEN

216 posts

Master Geek
+1 received by user: 25

ID Verified

#302278 12-Nov-2022 09:07
Send private message

Hey guys, I've got a domain with Metaname and am not super well versed with DNS and related technologies. I've managed to set up a Cloudflare tunnel as I've moved my server to a location where I do not have access to ports 80 and 443 for my reverse proxy (Nginx Proxy Manager docker container on unRAID). To do this I've had to move my DNS to Cloudflare, which means I need to use a DNS challenge for the reverse proxy. I'm trying to create a wildcard certificate but to do so it seems  I need DNSSEC. The trouble I'm having is that Metaname's instructions require dnssec-tools, which haven't been updated since 2018 and I cannot get them to compile in WSL Ubuntu or Debian. Is there any way I can get some help with this, or is my best bet to create a Ubuntu 14.04 VM as dnssec-tools is available in the repository in 14.04?

Cheers in advance for any help!


Sean





Spending way too much time and money on Unraid servers!
Lenovo SR630: 2x Xeon Gold 5120, 384GB RAM, 2.4TB array, NVIDIA Tesla T4
Dell EMC Isilon NL410: 2x Xeon E5-2470 v2, 96GB RAM, 83.2TB array, NVIDIA Quadro K600
Dell PowerEdge R630: 2x Xeon E5-2640 v4, 384GB RAM, 1.2TB array, NVIDIA T400


Filter this topic showing only the reply marked as answer Create new topic
freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41030

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2995040 12-Nov-2022 09:33
Send private message

Sorry, I didn't understand. I use DNSSEC with Metaname and Cloudflare. I only had to change the NS to the Cloudflare ones and then add the DS records that Cloudflare showed to me when I enabled DNSSEC. No need for external tools or anything else.

 

The example below is for one of the domains (not Geekzone, as we use a custom NS):

 





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 




SEEN

216 posts

Master Geek
+1 received by user: 25

ID Verified

  #2995045 12-Nov-2022 09:47
Send private message

freitasm:

 

The example below is for one of the domains (not Geekzone, as we use a custom NS):

 

 

Thank you so much Mauricio! A simple case of not understanding DNSSEC and not seeing the DS records section. You have saved me a huge headache and reminded me to read everything before I try to make changes!

 

 

 

EDIT: I don't have a "DS records" section, that's why I couldn't see it. Looks like I'm back to square one.

 

 

 





Spending way too much time and money on Unraid servers!
Lenovo SR630: 2x Xeon Gold 5120, 384GB RAM, 2.4TB array, NVIDIA Tesla T4
Dell EMC Isilon NL410: 2x Xeon E5-2470 v2, 96GB RAM, 83.2TB array, NVIDIA Quadro K600
Dell PowerEdge R630: 2x Xeon E5-2640 v4, 384GB RAM, 1.2TB array, NVIDIA T400


freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41030

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2995057 12-Nov-2022 10:07
Send private message

Does the option appear after you change the NS?




Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 




SEEN

216 posts

Master Geek
+1 received by user: 25

ID Verified

  #2995060 12-Nov-2022 10:26
Send private message

freitasm: Does the option appear after you change the NS?

 

Unfortunately no, it does not. That was my first thought too. I will change it back to Metaname's NS and give it time to propagate and see if it comes up then. I have also sent them a contact email regarding this but I don't expect to hear from them until Monday.





Spending way too much time and money on Unraid servers!
Lenovo SR630: 2x Xeon Gold 5120, 384GB RAM, 2.4TB array, NVIDIA Tesla T4
Dell EMC Isilon NL410: 2x Xeon E5-2470 v2, 96GB RAM, 83.2TB array, NVIDIA Quadro K600
Dell PowerEdge R630: 2x Xeon E5-2640 v4, 384GB RAM, 1.2TB array, NVIDIA T400


SEEN

216 posts

Master Geek
+1 received by user: 25

ID Verified

  #2995061 12-Nov-2022 10:30
Send private message

I have noticed that it looks like I might be able to update the DS records with the API though, so that could be an option





Spending way too much time and money on Unraid servers!
Lenovo SR630: 2x Xeon Gold 5120, 384GB RAM, 2.4TB array, NVIDIA Tesla T4
Dell EMC Isilon NL410: 2x Xeon E5-2470 v2, 96GB RAM, 83.2TB array, NVIDIA Quadro K600
Dell PowerEdge R630: 2x Xeon E5-2640 v4, 384GB RAM, 1.2TB array, NVIDIA T400


evilonenz
/dev/urandom
291 posts

Ultimate Geek
+1 received by user: 152

ID Verified
Trusted
Lifetime subscriber

  #2995063 12-Nov-2022 10:43
Send private message

You need to enable this in your account settings, should hopefully work fine once done:

 





Smokeping

 

Referral Links:

 

Quic - Use code R536299EPGOCN at checkout for free setup
Contact Energy - Use code FRTQDXB for $100 credit


 
 
 

Want to support Geekzone and browse the site without the ads? Subscribe to Geekzone now (monthly, annual and lifetime options).
SEEN

216 posts

Master Geek
+1 received by user: 25

ID Verified

  #2995064 12-Nov-2022 10:55
Send private message

Found an option to turn DNSSEC on in the account settings. Feel even more silly now! Thanks for your help Mauricio :)

 

 

I will reply and ask the topic to be locked if it works!





Spending way too much time and money on Unraid servers!
Lenovo SR630: 2x Xeon Gold 5120, 384GB RAM, 2.4TB array, NVIDIA Tesla T4
Dell EMC Isilon NL410: 2x Xeon E5-2470 v2, 96GB RAM, 83.2TB array, NVIDIA Quadro K600
Dell PowerEdge R630: 2x Xeon E5-2640 v4, 384GB RAM, 1.2TB array, NVIDIA T400


SEEN

216 posts

Master Geek
+1 received by user: 25

ID Verified

  #2995065 12-Nov-2022 10:56
Send private message

evilonenz:

 

You need to enable this in your account settings, should hopefully work fine once done:

 

 

Thanks! I didn't see this until after I'd found it myself haha





Spending way too much time and money on Unraid servers!
Lenovo SR630: 2x Xeon Gold 5120, 384GB RAM, 2.4TB array, NVIDIA Tesla T4
Dell EMC Isilon NL410: 2x Xeon E5-2470 v2, 96GB RAM, 83.2TB array, NVIDIA Quadro K600
Dell PowerEdge R630: 2x Xeon E5-2640 v4, 384GB RAM, 1.2TB array, NVIDIA T400


Filter this topic showing only the reply marked as answer Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.