Enable DNSSEC support in systemd-resolved

Enable DNSSEC support in systemd-resolved

I'm currently running Ubuntu 18.04 and I noticed that by default I was using systemd-resolved for DNS:

stanislas@xps ~> cat /etc/resolv.conf
# This file is managed by man:systemd-resolved(8). Do not edit.
#
# This is a dynamic resolv.conf file for connecting local clients to the
# internal DNS stub resolver of systemd-resolved. This file lists all
# configured search domains.
#
# Run "systemd-resolve --status" to see details about the uplink DNS servers
# currently in use.
#
# Third party programs must not access this file directly, but only through the
# symlink at /etc/resolv.conf. To manage man:resolv.conf(5) in a different way,
# replace this symlink by a static file or a different symlink.
#
# See man:systemd-resolved.service(8) for details about the supported modes of
# operation for /etc/resolv.conf.

nameserver 127.0.0.53

Most of the recent systemd distributions use it, Ubuntu does since 16.10. It has the same role as dnsmasq.

By playing around a bit with the service, I noticed DNSSEC checking was disabled:

stanislas@xps ~> systemd-resolve --status | grep DNSSEC
          DNSSEC NTA: 10.in-addr.arpa
      DNSSEC setting: no
    DNSSEC supported: no

It was confirmed by the config file:

stanislas@xps ~> grep DNSSEC /etc/systemd/resolved.conf
#DNSSEC=

Which I modified to DNSSEC=yes.

After restarting the service, I was able to confirm that I was now verifying DNSSEC!

sudo systemctl restart systemd-resolved
stanislas@xps ~> systemd-resolve --status | grep DNSSEC
          DNSSEC NTA: 10.in-addr.arpa
      DNSSEC setting: yes
    DNSSEC supported: yes
stanislas@xps ~> dig www.dnssec-failed.org | grep status
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 50750
https://dnssec.vs.uni-due.de/
Stanislas
Author
Stanislas
I like building things with code and computers

Comments

8Atom feed
Markdown supported
  1. Anonymous

    Thanks, quick, easy to understand

  2. Anonymous

    Thanks! Very helpful.

  3. Anonymous

    Thanks!

  4. Kenneth

    I'm failing somewhere with this whole dns tls.. thank you for this though.

    My issue resides with NetworkConnections > Additional DNS servers: Automatic, addresses only ipv4 127.0.0.1 ipv6 ::1

    If I don't add the ipv6 nameserver all is well... I dunno

  5. Yawob

    Great help. Thanks

  6. Matthew

    Hello, I got the info that: #DNSSEC=no but, how to change this value to "yes"? Thanks a lot!

    1. Jonathan Stewart

      Edit the file with a text editor, with elevated permissions.

      Try a command like this:

      sudo nano /etc/systemd/resolvd.conf

  7. Wanne

    Hey: I get the thumbs up even if I use an resolver that definitively does no validation.