unbound-daemon: unable to use DoT error: SSL_write syscall: Connection reset by peer
Nobody has claimed this yet.
- Dominant language
- Makefile
- Stars
- 4.6k
- Forks
- 4k
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 134
Description
Maintainer: @ericluehrsen @BKPepe @hardfalcon
Environment: (put here arch, model, OpenWrt version)
Model | GL.iNet GL-MT1300
Architecture | MediaTek MT7621 ver:1 eco:3
Firmware Version | OpenWrt SNAPSHOT r21222+1-ceb1451c10 / LuCI Master git-22.312.55390-37468c9
Kernel Version | 5.15.77
Description:
unbound is not able to use DNS over TLS. Any request will generate the log error: SSL_write syscall: Connection reset by peer. This seems to be an arch-related problem. DoT was working in unbound 1.13.x
Config: unbound.txt
See also: https://forum.openwrt.org/t/unbound-dns-over-tls-problem-on-master/109569
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the attached unbound.txt configuration and reproduce a DNS-over-TLS request on the listed GL-MT1300 hardware and firmware. Compare behavior with unbound 1.13.x, where DoT worked, and the reported snapshot; done means DoT requests complete without the SSL_write connection-reset error.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- linux
- Domain
- networking
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100