Commit Graph

483 Commits

Author SHA1 Message Date
Aminda Suomalainen abb0c37ef2
unbound.conf.d: add yggdrasil-override.conf
Begins #89 at a better time
2020-12-15 20:34:01 +02:00
Aminda Suomalainen b26c9f698d
chrony/yggdrasil: add Etro 2020-12-15 14:30:30 +02:00
Aminda Suomalainen b20f3367b1
systemd/yggdrasil: add mullvad-exclude (& fix chrony override typo) 2020-12-09 09:38:49 +02:00
Aminda Suomalainen 36b6a99e85
chrony.d: local-servers: add notes + xleave to the first comment 2020-12-09 08:44:34 +02:00
Aminda Suomalainen 40d535f2c0
systemd/chrony.service.d/mullvad-exclude: actually fix this 2020-12-08 18:36:34 +02:00
Aminda Suomalainen f92b8d8d05
chrony.d/yggdrasil.conf: add y.Jolly-Roger 2020-12-06 19:49:12 +02:00
Aminda Suomalainen e27e88efd8
chrony.d: add hwtimestamp.conf 2020-12-06 19:26:04 +02:00
Aminda Suomalainen 4a25481db2
chrony/yggdrasil.conf: add Sedric 2020-12-06 18:36:23 +02:00
Aminda Suomalainen 5e94147e81
chrony.d/yggdrasil.conf: initial commit 2020-12-06 18:02:43 +02:00
Aminda Suomalainen 2a615d8241
chrony: note that confdir and NTS require 4.0 2020-12-03 10:52:47 +02:00
Aminda Suomalainen e9aefd711b
blocklist.conf: refuse blocked instead of nxdomain
Only the Firefox DoH needs to be NXDOMAIN while REFUSE may be more
accurate for the rest.
2020-11-21 12:13:55 +02:00
Aminda Suomalainen e7a6e00b83
unbound/dns-over-tls: comment Adguard & NextDNS for not being in FI 2020-11-15 09:46:50 +02:00
Aminda Suomalainen aadcc009a0
unbound/dns-over-tls.conf: add Adguard (unfiltered) & NextDNS 2020-11-12 16:12:18 +02:00
Aminda Suomalainen 3289a812ee
unbound: add dns-mullvad.conf (not encrypted)
Contains Mullvad Wireguard, OpenVPN and public addresses
2020-11-10 16:04:48 +02:00
Aminda Suomalainen 9536101263
resolv.csv: add BlahDNS DoH CDNs
Just doh1, because it and doh2 resolve into the same addresses for me
and I don't want to add duplicate DoH field when only BlahDNS has two
differnt addresses for the same thing.
2020-11-08 12:50:31 +02:00
Aminda Suomalainen 49d969822b
etc/resolv.csv: add BlahDNS
Resolves: #85
2020-11-04 12:56:48 +02:00
Aminda Suomalainen c302b10caf
chrony.d: restore log.conf 2020-11-01 11:57:57 +02:00
Aminda Suomalainen 07e8c52f3b
chrony.d/local-servers: remove duplicate line
it's in README.md
2020-11-01 11:36:30 +02:00
Aminda Suomalainen dced82b820
etc/chrony: break chrony.conf into README.md & chrony.d/ 2020-11-01 11:23:59 +02:00
Aminda Suomalainen 52458cc8aa
chrony.conf: add xleave for peer 2020-11-01 10:47:30 +02:00
Aminda Suomalainen 84a669f51f
chrony.conf: add note for Windows on nettime 2020-10-31 18:10:25 +02:00
Aminda Suomalainen c55e6b97e8
chrony.conf: comments for nmap and VPNs 2020-10-31 14:34:47 +02:00
Aminda Suomalainen 0c7038da14
systemd: systemd-resolved.service.d/unbound.conf: After unbound 2020-10-30 10:19:39 +02:00
Aminda Suomalainen fe83cbbb3a
systemd: add config for excluding Chrony from Mullvad 2020-10-30 08:04:58 +02:00
Aminda Suomalainen f878041e2e
unbound/dns-over-tls.conf: reverse order of providers
It seems to have some (small?) relevance to where queries go to.
2020-10-29 16:24:52 +02:00
Aminda Suomalainen 6e1f41533c
unbound/dns-over-tls.conf: comment the 443 appliedprivacy
Thinking it a bit more, it's not useful to use their resources on
devices that practically never encounter blocked port 853.
2020-10-29 13:22:19 +02:00
Aminda Suomalainen b03e00faaa
local/share/apps: add firejailed mirage (todo: test it) 2020-10-29 13:15:48 +02:00
Aminda Suomalainen c93034ba7f
unbound/dns-over-tls.conf: major cleanup 2020-10-29 13:15:23 +02:00
Aminda Suomalainen 8b04c26065
chrony.conf: add a peer comment for LOCALMACHINE.local 2020-10-27 10:35:09 +02:00
Aminda Suomalainen dc2ac02412
begin depulseaudioing
https://wiki.archlinux.org/index.php/PulseAudio/Troubleshooting#No_sound_below_a_volume_cutoff_or_Clipping_on_a_particular_output_device
is too much for me. I expect to suffer this decision too though.

* i3: bind audio buttons to amixer (TODO: there are still pulse-specific
  shortcuts and no shortcut for any kind of a mixer. $TERMINAL
  alsamixer?)
* i3status: comment pulse to make it see alsa
* apt: pin pulseaudio to negative priority
2020-10-26 17:21:39 +02:00
Aminda Suomalainen 9b197cbaed
chrony.conf: add a local server example 2020-10-26 07:34:10 +02:00
Aminda Suomalainen 258cf72ccb
chrony.conf: mark Cloudflare as a pool of 2 2020-10-25 19:46:36 +02:00
Aminda Suomalainen 9ae9856c0a
chrony.conf: mark Snopyta & Telia as pools with maxsources 3 2020-10-25 18:54:53 +02:00
Aminda Suomalainen 51080f52d8
chrony.conf: add comments on allowing lan access 2020-10-25 17:43:07 +02:00
Aminda Suomalainen b4ca31e6c6
chrony.conf: add DNA & Telia NTP servers
Resolves: #83
2020-10-25 17:22:59 +02:00
Aminda Suomalainen 4cebe7fbd5
chrony.conf: list NTP servers
Ref: #83
2020-10-25 12:44:53 +02:00
Aminda Suomalainen 993759577e
Bind systemd-resolved to Unbound 2020-10-25 09:05:07 +02:00
Aminda Suomalainen 73f273f4bb
etc/chrony: add small chrony.conf notes 2020-10-24 11:32:07 +03:00
Aminda Suomalainen d3e00fb1a3
xdg-applications: add firejailed appimage of chatterino 2020-10-24 09:11:14 +03:00
Aminda Suomalainen 1e70d7d4d7
etc/systemd-resolved&unbound: add Quad9 ECS configs
Untested. The last time I saw the documentation, they didn't mention
DoT.
2020-10-21 17:09:20 +03:00
Aminda Suomalainen 1467454284
hosts.append: prepend empty line
It makes it easier to see where this begins in the appended /etc/hosts
2020-10-21 15:18:03 +03:00
Aminda Suomalainen de7184794a
etc: add hosts.append for appending into hosts for systemd-resolved 2020-10-21 15:16:56 +03:00
Aminda Suomalainen ca4c85b7df
etc/resolv.csv: add Quad9 ECS
The DoT address is guessed and verified to be open through nmap, as it's
not documented, I don't know surely that it's what it should.

DoH is mentioned in https://www.quad9.net/doh-quad9-dns-servers/

via https://gitlab.com/nitrohorse/ios14-encrypted-dns-mobileconfigs/-/issues/6
2020-10-18 11:11:27 +03:00
Aminda Suomalainen cb5781044c
resolv.conf: add OpenDNS Family 2020-10-03 14:56:52 +03:00
Aminda Suomalainen 5f9cf10c68
resolv.csv: add Cleanbrowsing 2020-10-03 14:07:41 +03:00
Aminda Suomalainen 531abc1f42
resolv.csv: fix Cloudflare DoT address 2020-10-03 13:49:04 +03:00
Aminda Suomalainen 96d19d99cb
resolv.csv: add Cloudflare family, fill CF antimalware IPv6 2020-10-03 13:46:13 +03:00
Aminda Suomalainen 8241d0e695
resolv.csv: add AdGuard Family 2020-10-03 13:42:05 +03:00
Aminda Suomalainen ae533261ab
etc/resolv.csv restore Firefox addresses 2020-10-03 13:38:31 +03:00
Aminda Suomalainen 13a03812ba
resolv.conf: move resolvers to resolv.csv 2020-09-27 15:05:53 +03:00