7113fda702 
							
						 
					 
					
						
						
							
							sudoers.d/nordvpnd: add restarting unbound & systemd-resolved  
						
						
						
						
					 
					
						2024-04-24 18:00:00 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							32c5da4422 
							
						 
					 
					
						
						
							
							etc/resolv.conf-generate.bash: also be verbose with chattr & chmod  
						
						
						
						
					 
					
						2024-04-24 12:09:15 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							9b01bc5260 
							
						 
					 
					
						
						
							
							etc/hosts/README.md: add forgotten blocklist and formatting  
						
						
						
						
					 
					
						2024-04-24 11:55:35 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							c00f750d96 
							
						 
					 
					
						
						
							
							etc/resolv.conf-generate.bash: simple resolv.conf writer the way I want  
						
						
						
						
					 
					
						2024-04-24 11:06:35 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							fa9da0901d 
							
						 
					 
					
						
						
							
							etc/hosts/blocklist: initial commit  
						
						
						
						
					 
					
						2024-04-24 09:21:42 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							b36ba70a70 
							
						 
					 
					
						
						
							
							systemd/service.d: add resolv.conf example with warnings  
						
						
						
						
					 
					
						2024-04-24 07:31:10 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							bdcd7249c3 
							
						 
					 
					
						
						
							
							etc/resolv.conf: fix comment  
						
						
						
						
					 
					
						2024-04-23 16:47:03 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							95e17d0a49 
							
						 
					 
					
						
						
							
							resolv.conf: remove rotate comments, attempt to explain the logic behind timeout & attempts  
						
						
						
						
					 
					
						2024-04-23 16:23:36 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							425af3eabf 
							
						 
					 
					
						
						
							
							etc/resolv.conf: specify timeout 1 and attempts 5  
						
						
						
						
					 
					
						2024-04-23 16:03:49 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							70ed890742 
							
						 
					 
					
						
						
							
							dnf/protected.d: add README.md, aminda-{desktop,essentials}.conf  
						
						
						
						
					 
					
						2024-04-23 07:51:29 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							4dac26e46e 
							
						 
					 
					
						
						
							
							dnf: also protect unbound  
						
						
						
						
					 
					
						2024-04-23 07:41:49 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							b0f7876436 
							
						 
					 
					
						
						
							
							etc/dnf/protected.d: add systemd-{networkd,resolved}.conf  
						
						
						
						
					 
					
						2024-04-23 07:29:18 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							f41e80d66a 
							
						 
					 
					
						
						
							
							hosts/dns: comment where it begins and where it ends  
						
						
						
						
					 
					
						2024-04-22 17:11:03 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							97c2e74220 
							
						 
					 
					
						
						
							
							etc/hosts: attempt to perform the bad idea of well-known DNS servers here instead  
						
						
						
						
					 
					
						2024-04-22 16:24:51 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							4560e776df 
							
						 
					 
					
						
						
							
							systemd-{resolved,networkd}: just break things  
						
						
						
						
					 
					
						2024-04-22 15:43:50 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							886b8dbfbd 
							
						 
					 
					
						
						
							
							unbound.conf.d: well-known-dns.conf -> well-known-dns.conf.badidea  
						
						... 
						
						
						
						This will break DNSSEC and a lot of things. 
						
						
					 
					
						2024-04-22 15:39:47 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							4acd22dc37 
							
						 
					 
					
						
						
							
							systemd-networkd: add untested none (Yggdrasil) & wireguard configuration  
						
						
						
						
					 
					
						2024-04-22 15:17:14 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							6ea0a570dd 
							
						 
					 
					
						
						
							
							systemd-networkd: match systemd-resolved configuration  
						
						
						
						
					 
					
						2024-04-22 15:12:07 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							dea732d15b 
							
						 
					 
					
						
						
							
							systemd-resolved: attempt to simplify configuration  
						
						
						
						
					 
					
						2024-04-22 15:08:03 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							f976c9a530 
							
						 
					 
					
						
						
							
							etc/resolv.conf: comment rotate, remove bad search domain comment  
						
						
						
						
					 
					
						2024-04-22 14:51:58 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							895359ff67 
							
						 
					 
					
						
						
							
							etc/resolv.conf: add warning about mixing systemd-resolved & unbound  
						
						
						
						
					 
					
						2024-04-22 14:50:37 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							903e38f307 
							
						 
					 
					
						
						
							
							systemd-networkd: unset other DNS  
						
						
						
						
					 
					
						2024-04-22 13:32:12 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							7be1800002 
							
						 
					 
					
						
						
							
							systemd-networkd: disable DNSSEC/DNSOverTLS by default as localhost  
						
						
						
						
					 
					
						2024-04-22 13:16:14 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							3d58aee508 
							
						 
					 
					
						
						
							
							systemd-networkd/10-ether.network: mention unmanaged/NetworkManager  
						
						
						
						
					 
					
						2024-04-22 13:09:28 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							e56e5e1909 
							
						 
					 
					
						
						
							
							systemd-networkd: remove comment I don't stand behind  
						
						
						
						
					 
					
						2024-04-22 13:05:58 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							02c434b81b 
							
						 
					 
					
						
						
							
							systemd-networkd: list local DNS resolvers  
						
						
						
						
					 
					
						2024-04-22 12:59:38 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							44b6e5b618 
							
						 
					 
					
						
						
							
							systemd-networkd: add DNSSEC & DNSOverTLS & search domains  
						
						
						
						
					 
					
						2024-04-22 12:25:25 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							945ca0462d 
							
						 
					 
					
						
						
							
							Revert "systemd-networkd: attempt to deduplicate by cutting into 10-global.network"  
						
						... 
						
						
						
						This reverts commit 19b6fbef3c2470bbdd9236d1bc1d2998d6893991. 
						
						
					 
					
						2024-04-22 12:21:56 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							06787a38de 
							
						 
					 
					
						
						
							
							resolved/00-no-local-resolver.conf: comment local resolver since I break DNSSEC  
						
						
						
						
					 
					
						2024-04-22 12:14:34 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							19b6fbef3c 
							
						 
					 
					
						
						
							
							systemd-networkd: attempt to deduplicate by cutting into 10-global.network  
						
						
						
						
					 
					
						2024-04-22 12:07:39 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							aac3ccdec3 
							
						 
					 
					
						
						
							
							unbound/well-known-dns.conf: add CNAMEs one.one.one.one & dns.google.com  
						
						
						
						
					 
					
						2024-04-22 11:26:46 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							dc6fc85174 
							
						 
					 
					
						
						
							
							chromium: exclude bittimittari.fi  
						
						
						
						
					 
					
						2024-04-22 10:09:28 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							fe1970cfd9 
							
						 
					 
					
						
						
							
							chromium: add brave IPFS disabling policy  
						
						... 
						
						
						
						IPFS is known for killing routers and having it on two machines while trying to VoIP with a lot of people, it gets a bit too heavy 
						
						
					 
					
						2024-04-22 10:03:53 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							abd21e008a 
							
						 
					 
					
						
						
							
							well-known-dns.conf: typetransparent subdomains just in case  
						
						... 
						
						
						
						Theoretically the higher level domain affects them too, but in practice I am unsure and I have previously only used always_reject for google-analytics & subdomains blocking. It at least isn't causing warnings or errors. 
						
						
					 
					
						2024-04-22 07:42:53 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							579e98f27c 
							
						 
					 
					
						
						
							
							unbound/well-known-dns.conf: use typetransparent so non-local queries won't get NODATA  
						
						
						
						
					 
					
						2024-04-22 07:28:55 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							623a9150fd 
							
						 
					 
					
						
						
							
							unbound: merge 00-insecure-domains.conf into blocklist.conf  
						
						
						
						
					 
					
						2024-04-22 07:10:18 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							892feb3c1b 
							
						 
					 
					
						
						
							
							unbound/blocklist: add fritz.box.  
						
						
						
						
					 
					
						2024-04-22 07:06:21 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							c90b551ac4 
							
						 
					 
					
						
						
							
							chromium: merge doh-forced to the doh files due to it being required anyway, update documentation, rename doh-allowed → doh-unlocked-unset  
						
						
						
						
					 
					
						2024-04-21 14:00:39 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							4a47d14069 
							
						 
					 
					
						
						
							
							resolved.conf.d: add dot-trex.conf symlink and explaining comments like in unbound  
						
						
						
						
					 
					
						2024-04-21 13:14:53 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							ce9159e756 
							
						 
					 
					
						
						
							
							unbound/dot-quad9.conf: prettier sorting  
						
						
						
						
					 
					
						2024-04-21 13:13:41 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							7379241a20 
							
						 
					 
					
						
						
							
							chromium: add the rest of Quad9 & update README.md  
						
						
						
						
					 
					
						2024-04-21 11:35:28 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							3540f2442e 
							
						 
					 
					
						
						
							
							chromium/doh-quad9*: add alternative port as Chromium allows multiple  
						
						
						
						
					 
					
						2024-04-21 11:28:07 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							eb47fac4cb 
							
						 
					 
					
						
						
							
							systemd-resolved: add vim modelines  
						
						
						
						
					 
					
						2024-04-21 10:58:45 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							f126e681a2 
							
						 
					 
					
						
						
							
							systemd-resolved: split applied-privacy#443 to its own file as resolved configs don't exclude each other  
						
						
						
						
					 
					
						2024-04-21 10:57:25 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							a0ccd790ab 
							
						 
					 
					
						
						
							
							unbound & systemd-resolved: add Quad9 alternative port  
						
						
						
						
					 
					
						2024-04-21 10:54:22 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							e64e4e7fd0 
							
						 
					 
					
						
						
							
							firefox: DisableEncryptedClientHello: false  
						
						... 
						
						
						
						I am not sure if this does anything, I just saw a message in logs and it didn't trigger an error 
						
						
					 
					
						2024-04-21 10:13:29 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							6a97040386 
							
						 
					 
					
						
						
							
							firefox: add IPvFoo*  
						
						
						
						
					 
					
						2024-04-21 10:08:43 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							069da00a38 
							
						 
					 
					
						
						
							
							Chromium: add IPvFoo* and note that users should go through extensions  
						
						
						
						
					 
					
						2024-04-21 09:58:30 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							e6bd2b13ad 
							
						 
					 
					
						
						
							
							unbound: add TREX upstream configuration  
						
						
						
						
					 
					
						2024-04-20 20:25:48 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							a7cf718453 
							
						 
					 
					
						
						
							
							uncound/well-known-dns.conf: add DNS0 {Zero,Kids,Open}  
						
						
						
						
					 
					
						2024-04-20 17:59:46 +03:00