Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Litttlesnitch & Stubby #64

Open
inudge opened this issue Jan 7, 2018 · 5 comments
Open

Litttlesnitch & Stubby #64

inudge opened this issue Jan 7, 2018 · 5 comments

Comments

@inudge
Copy link

inudge commented Jan 7, 2018

Hi,

Firstly, thank you very much for building Stubby (+getdns), I am a very happy user of this software.

It seems logical to me that people who use Stubby are fairly likely to also run the popular Littlesnitch firewall app. At the moment this can be quite tricky. For example, I recently experienced very strange Stubby behaviour until I realised that Littlesnitch was blocking the download of the root anchor from data.iana.org. AFAICT, there was no specific error messages from Stubby about this and it took me a while to diagnose the issue. Secondly, Littlesnitch doesn't work well with unsigned code. I guess many people do automatic Homebrew updates but that requires reauthorising everything within Littlesnitch due to the unsigned code. If you are managing Macs via SSH this is quite painful since it's not possible (AFAIK) to update Littlesnitch rules other than via the GUI.

I realise that Stubby is only recommended for technical users at the moment but if there's anything you can do to make it a little more Littlesnitch friendly, that would be very helpful.

Thanks !

@wtoorop
Copy link
Contributor

wtoorop commented Jan 15, 2018

Thanks Inudge, I'll try to redirect more logging from getdns through the interface that Stubby also uses.
That would make problems with Zero configuration DNSSEC more apparent.

@inudge
Copy link
Author

inudge commented Jan 15, 2018

Great, thanks !
I've contacted Objective Development (Littlesnitch devs) to ask for advise regarding updates to homebrew managed apps. Will let you know what they say. In fact, it probably has little to do with being unsigned.

@inudge
Copy link
Author

inudge commented Jan 15, 2018

I just wanted to add that when I had the issue with the blocked download from data.iana.org and didn't see any error about that, I was running stubby with the -l (debug-level) logging option enabled.

@wtoorop
Copy link
Contributor

wtoorop commented Jan 16, 2018

I know Inudge. Not all logging from getdns is directed to the interface from which Stubby can pick it up and show; I'll start improving on that soon.

@wtoorop wtoorop pinned this issue Feb 20, 2020
@wtoorop
Copy link
Contributor

wtoorop commented Feb 20, 2020

Logging of anchor fetching has been converted, but stubby shows only log system GETDNS_LOG_UPSTREAM_STATS . To resolve we need to add an option to do logging for the other systems as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants