aboutsummaryrefslogtreecommitdiff
path: root/assets/outbox/2026-07-01-2143-from-rulesets-archsetup-tooling-note.txt
diff options
context:
space:
mode:
authorCraig Jennings <c@cjennings.net>2026-09-13 07:02:39 -0500
committerCraig Jennings <c@cjennings.net>2026-09-13 07:02:39 -0500
commit2e303a07d1a6e4de85277a34669f8da61f7fdb6e (patch)
treef428bcf0ce3a69cfb4ef589e16d7f262f1fd5d07 /assets/outbox/2026-07-01-2143-from-rulesets-archsetup-tooling-note.txt
parente73b5a48196a961608a8d1d69a4bd309143fb8d4 (diff)
downloadarchsetup-2e303a07d1a6e4de85277a34669f8da61f7fdb6e.tar.gz
archsetup-2e303a07d1a6e4de85277a34669f8da61f7fdb6e.zip
feat(install): default DNS over TLS off on the Proton tunnel links
The resolved drop-in pins DNSOverTLS=yes for every link. Proton VPN (proton0) and the static Proton WireGuard profiles (wgpvpn) push an in-tunnel resolver (10.2.0.1) that answers plain port 53 and never completes TLS on 853, so every lookup through the tunnel hung. The Proton client recreates its NetworkManager profile on each connect, so a per-profile setting can't stick. NM pushes a [connection-tunnel-dot] default matched on those two interface names to resolved on every activation. Wifi and everything else keep the strict setting. Ratio and velox already carry the drop-in by hand. This makes a rebuild carry it too.
Diffstat (limited to 'assets/outbox/2026-07-01-2143-from-rulesets-archsetup-tooling-note.txt')
0 files changed, 0 insertions, 0 deletions