Paul Wouters 7ac9ae
# Fedora/EPEL version of dnssec-trigger.conf
Paul Wouters 9fcdf7
Paul Wouters 9fcdf7
# logging detail, 0=only errors, 1=operations, 2=detail, 3,4 debug detail.
Paul Wouters 9fcdf7
# verbosity: 1
Paul Wouters 9fcdf7
Paul Wouters 9fcdf7
# pidfile location
Paul Wouters 9fcdf7
pidfile: "/var/run/dnssec-triggerd.pid"
Paul Wouters 9fcdf7
Paul Wouters 9fcdf7
# log to a file instead of syslog, default is to syslog
Paul Wouters 9fcdf7
# logfile: "/var/log/dnssec-trigger.log"
Paul Wouters 9fcdf7
Paul Wouters 9fcdf7
# log to syslog, or (log to to stderr or a logfile if specified). yes or no.
Paul Wouters 9fcdf7
# use-syslog: yes
Paul Wouters 9fcdf7
Paul Wouters 9fcdf7
# chroot to this directory
Paul Wouters 9fcdf7
# chroot: ""
Paul Wouters 9fcdf7
Paul Wouters 9fcdf7
# the unbound-control binary if not found in PATH.
Paul Wouters 9fcdf7
# commandline options can be appended "unbound-control -c my.conf" if you wish.
Paul Wouters 9fcdf7
# unbound-control: "/usr/sbin/unbound-control"
Paul Wouters 9fcdf7
Paul Wouters 9fcdf7
# where is resolv.conf to edit.
Paul Wouters 9fcdf7
# resolvconf: "/etc/resolv.conf"
Paul Wouters 9fcdf7
Paul Wouters 9fcdf7
# the domain example.com line (if any) to add to resolv.conf(5). default none.
Paul Wouters 9fcdf7
# domain: ""
Paul Wouters 9fcdf7
Paul Wouters 9fcdf7
# domain name search path to add to resolv.conf(5). default none.
Paul Wouters 9fcdf7
# the search path from DHCP is not picked up, it could be used to misdirect.
Paul Wouters 9fcdf7
# search: ""
Paul Wouters 9fcdf7
Paul Wouters 7ac9ae
# the command to run to open login pages on hot spots, a web browser.
Paul Wouters 7ac9ae
# empty string runs no command.
Paul Wouters 7ac9ae
# login-command: "xdg-open"
Paul Wouters 7ac9ae
Paul Wouters 7ac9ae
# the url to open to get hot spot login, it gets overridden by the hotspot.
Paul Wouters 7ac9ae
# login-location: "http://www.nlnetlabs.nl/projects/dnssec-trigger"
Paul Wouters 7ac9ae
# should to be a ttl=0 entry
Paul Wouters 7ac9ae
login-location: "http://hotspot-nocache.fedoraproject.org/"
Paul Wouters 7ac9ae
Paul Wouters 9fcdf7
# do not perform actions (unbound-control or resolv.conf), for a dry-run.
Paul Wouters 9fcdf7
# noaction: no
Paul Wouters 9fcdf7
Paul Wouters 9fcdf7
# port number to use for probe daemon.
Paul Wouters 9fcdf7
# port: 8955
Paul Wouters 9fcdf7
Paul Wouters 9fcdf7
# keys and certificates generated by the dnssec-trigger-keygen systemd service
Paul Wouters 9fcdf7
# (which called dnssec-trigger-control-setup)
Paul Wouters 9fcdf7
server-key-file: "/etc/dnssec-trigger/dnssec_trigger_server.key"
Paul Wouters 9fcdf7
server-cert-file: "/etc/dnssec-trigger/dnssec_trigger_server.pem"
Paul Wouters 9fcdf7
control-key-file: "/etc/dnssec-trigger/dnssec_trigger_control.key"
Paul Wouters 9fcdf7
control-cert-file: "/etc/dnssec-trigger/dnssec_trigger_control.pem"
Paul Wouters 9fcdf7
Paul Wouters 7ac9ae
# check for updates, download and ask to install them (for Windows, OSX).
Paul Wouters 7ac9ae
# check-updates: no
Paul Wouters 7ac9ae
Paul Wouters 7ac9ae
# webservers that are probed to see if internet access is possible.
Paul Wouters 7ac9ae
# They serve a simple static page over HTTP port 80.  It probes a random url:
Paul Wouters 7ac9ae
# after a space is the content expected on the page, (the page can contain
Paul Wouters 7ac9ae
# whitespace before and after this code).  Without urls it skips http probes.
Paul Wouters 7ac9ae
Paul Wouters 7ac9ae
# provided by NLnetLabs
Paul Wouters 7ac9ae
# It is provided on a best effort basis, with no service guarantee.
Paul Wouters 7ac9ae
# url: "http://ster.nlnetlabs.nl/hotspot.txt OK"
Paul Wouters 7ac9ae
Paul Wouters 7ac9ae
# provided by FedoraProject
Paul Wouters 7ac9ae
url: "http://fedoraproject.org/static/hotspot.txt OK"
Paul Wouters 7ac9ae
Paul Wouters 9fcdf7
# fallback open DNSSEC resolvers that run on TCP port 80 and TCP port 443.
Paul Wouters 9fcdf7
# the ssl443 adds an ssl server IP, if you specify a hash it is checked, put
Paul Wouters 9fcdf7
# the following on one line: ssl443:<space><IP><space><HASHoutput>
Paul Wouters 9fcdf7
# hash is output of openssl x509 -sha256 -fingerprint -in server.pem
Paul Wouters 9fcdf7
# You can add more with extra config lines.
Paul Wouters 9fcdf7
Paul Wouters dab22c
# Provided by fedoraproject.org, #fedora-admin
Paul Wouters dab22c
# It is provided on a best effort basis, with no service guarantee.
Tomas Hozza f8202e
ssl443: 140.211.169.201 A8:3E:DA:F0:12:82:55:7E:60:B5:B5:56:F1:66:BB:13:A8:BD:FC:B4:51:41:C0:F2:E7:8E:7B:64:AA:87:E6:F2
Tomas Hozza f8202e
tcp80:  140.211.169.201
Paul Wouters dab22c
ssl443: 66.35.62.163 A8:3E:DA:F0:12:82:55:7E:60:B5:B5:56:F1:66:BB:13:A8:BD:FC:B4:51:41:C0:F2:E7:8E:7B:64:AA:87:E6:F2
Paul Wouters 8201fd
tcp80:  66.35.62.163 
Paul Wouters dab22c
ssl443: 152.19.134.150 A8:3E:DA:F0:12:82:55:7E:60:B5:B5:56:F1:66:BB:13:A8:BD:FC:B4:51:41:C0:F2:E7:8E:7B:64:AA:87:E6:F2
Paul Wouters 8201fd
tcp80:  152.19.134.150 
Paul Wouters 09afdd
ssl443: 2610:28:3090:3001:dead:beef:cafe:fed9 A8:3E:DA:F0:12:82:55:7E:60:B5:B5:56:F1:66:BB:13:A8:BD:FC:B4:51:41:C0:F2:E7:8E:7B:64:AA:87:E6:F2
Paul Wouters 8201fd
tcp80:  2610:28:3090:3001:dead:beef:cafe:fed9 
Paul Wouters dab22c
Paul Wouters dab22c
# provided by Paul Wouters (pwouters@redhat.com)
Paul Wouters 9fcdf7
# It is provided on a best effort basis, with no service guarantee.
Paul Wouters dab22c
# tcp80:  193.110.157.123
Paul Wouters dab22c
# tcp80:  2001:888:2003:1004::123
Paul Wouters dab22c
# ssl443: 193.110.157.123 16:41:49:E0:9D:62:CD:DB:79:A7:2B:71:58:C4:D5:E8:70:FA:BF:4D:6D:36:CC:07:35:33:C0:16:17:1B:61:E7
Paul Wouters dab22c
# ssl443: 2001:888:2003:1004::123 16:41:49:E0:9D:62:CD:DB:79:A7:2B:71:58:C4:D5:E8:70:FA:BF:4D:6D:36:CC:07:35:33:C0:16:17:1B:61:E7
Paul Wouters 9fcdf7
Paul Wouters dab22c
# provided by NLnetLabs (www.nlnetlabs.nl)
Paul Wouters 9fcdf7
# It is provided on a best effort basis, with no service guarantee.
Paul Wouters 9fcdf7
# tcp80: 213.154.224.3
Paul Wouters 9fcdf7
# tcp80: 2001:7b8:206:1:bb::
Paul Wouters 9fcdf7
# ssl443: 213.154.224.3 DC:22:7B:1C:00:1A:CE:C5:48:49:B1:E3:30:DE:61:93:61:12:4E:CB:5C:B4:33:C4:BC:75:8C:D6:16:9D:F0:9F
Paul Wouters 9fcdf7
# ssl443: 2001:7b8:206:1:bb:: DC:22:7B:1C:00:1A:CE:C5:48:49:B1:E3:30:DE:61:93:61:12:4E:CB:5C:B4:33:C4:BC:75:8C:D6:16:9D:F0:9F
Paul Wouters 9fcdf7