Source
Test suite to validate using one or multiple ciphers to protect DoH connection
Valid Source
Description
Configures a valid source with the expected minisign key and checks that everything works.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server-name rd-server set service dns proxy source RD minisign-key RWQc0jv6ZbtYLlNXRWNMP/aXgCRsmXGZXJJZ38hPCe1//wTsa35BlF9p set service dns proxy source RD url 'http://10.215.168.1/~robot/RD-resolver.md' set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 2: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:
(?m)^.*\[rd-server\] OK \(DoH\) - rtt: \d+ms$Show output
Jul 24 10:25:50.356355 osdx systemd-journald[2180]: Runtime Journal (/run/log/journal/3a8dbab828fc40a183893e468c03e10b) is 1.9M, max 13.8M, 11.8M free. Jul 24 10:25:50.359425 osdx systemd-journald[2180]: Received client request to rotate journal, rotating. Jul 24 10:25:50.359484 osdx systemd-journald[2180]: Vacuuming done, freed 0B of archived journals from /run/log/journal/3a8dbab828fc40a183893e468c03e10b. Jul 24 10:25:50.369063 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal clear'. Jul 24 10:25:50.581505 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system coredump delete all'. Jul 24 10:25:50.833830 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu. Jul 24 10:25:50.974932 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Jul 24 10:25:51.029949 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Jul 24 10:25:51.134166 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'. Jul 24 10:25:51.198036 osdx ubnt-cfgd[558121]: inactive Jul 24 10:25:51.222629 osdx INFO[558130]: FRR daemons did not change Jul 24 10:25:51.251386 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Jul 24 10:25:51.302820 osdx WARNING[558201]: No supported link modes on interface eth0 Jul 24 10:25:51.304345 osdx modulelauncher[558201]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Jul 24 10:25:51.304360 osdx modulelauncher[558201]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Jul 24 10:25:51.305547 osdx modulelauncher[558201]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off -- Jul 24 10:25:51.305556 osdx modulelauncher[558201]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75. Jul 24 10:25:51.525637 osdx cfgd[1923]: [414651]Completed change to active configuration Jul 24 10:25:51.526223 osdx OSDxCLI[414651]: User 'admin' committed the configuration. Jul 24 10:25:51.555009 osdx OSDxCLI[414651]: User 'admin' left the configuration menu. Jul 24 10:25:51.748647 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Jul 24 10:25:51.834637 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal show | cat'. Jul 24 10:25:52.004319 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu. Jul 24 10:25:52.085593 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'. Jul 24 10:25:52.184561 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy source RD url http://10.215.168.1/~robot/RD-resolver.md'. Jul 24 10:25:52.260777 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy source RD minisign-key RWQc0jv6ZbtYLlNXRWNMP/aXgCRsmXGZXJJZ38hPCe1//wTsa35BlF9p'. Jul 24 10:25:52.360998 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy server-name rd-server'. Jul 24 10:25:52.453734 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'. Jul 24 10:25:52.534634 osdx ubnt-cfgd[558306]: inactive Jul 24 10:25:52.555882 osdx INFO[558315]: FRR daemons did not change Jul 24 10:25:52.570106 osdx ca-certificates[558331]: Updating certificates in /etc/ssl/certs... Jul 24 10:25:53.133461 osdx ubnt-cfgd[559343]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Jul 24 10:25:53.142497 osdx ca-certificates[559348]: 1 added, 0 removed; done. Jul 24 10:25:53.146037 osdx ca-certificates[559355]: Running hooks in /etc/ca-certificates/update.d... Jul 24 10:25:53.149773 osdx ca-certificates[559357]: done. Jul 24 10:25:53.223770 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Jul 24 10:25:53.233408 osdx cfgd[1923]: [414651]Completed change to active configuration Jul 24 10:25:53.233829 osdx OSDxCLI[414651]: User 'admin' committed the configuration. Jul 24 10:25:53.246714 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] dnscrypt-proxy 2.0.45 Jul 24 10:25:53.247003 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] Network connectivity detected Jul 24 10:25:53.247034 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] Dropping privileges Jul 24 10:25:53.249580 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] Network connectivity detected Jul 24 10:25:53.249645 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Jul 24 10:25:53.249645 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Jul 24 10:25:53.251898 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [WARNING] /var/cache/dnscrypt-proxy/RD.md: open /var/cache/dnscrypt-proxy/sf-zsrhfhpfhbjezmxq.tmp: permission denied Jul 24 10:25:53.251898 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] Source [RD] loaded Jul 24 10:25:53.252096 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [WARNING] Missing stamp for server [server-name`] Jul 24 10:25:53.252123 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [WARNING] Error in source [RD]: [Missing stamp for server [server-name`]] -- Continuing with reduced server count [1] Jul 24 10:25:53.252123 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] Firefox workaround initialized Jul 24 10:25:53.252123 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] Loading the set of cloaking rules from [/tmp/tmph0bc7q1h] Jul 24 10:25:53.253457 osdx OSDxCLI[414651]: User 'admin' left the configuration menu. Jul 24 10:25:53.400220 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] [rd-server] OK (DoH) - rtt: 122ms Jul 24 10:25:53.400220 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] Server with the lowest initial latency: rd-server (rtt: 122ms) Jul 24 10:25:53.400220 osdx dnscrypt-proxy[559361]: [2026-07-24 10:25:53] [NOTICE] dnscrypt-proxy is ready - live servers: 1 Jul 24 10:25:53.408014 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal show | cat'.
Valid Source With Prefix
Description
Configures a valid source with the expected minisign key and checks that everything works. Additionally, uses a prefix to avoid the duplicity of servers with the same name.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy server-name PRIVATE-rd-server set service dns proxy source RD minisign-key RWQc0jv6ZbtYLlNXRWNMP/aXgCRsmXGZXJJZ38hPCe1//wTsa35BlF9p set service dns proxy source RD prefix PRIVATE- set service dns proxy source RD url 'http://10.215.168.1/~robot/RD-resolver.md' set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 2: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:
(?m)^.*\[PRIVATE-rd-server\] OK \(DoH\) - rtt: \d+ms$Show output
Jul 24 10:26:02.370171 osdx systemd-journald[2180]: Runtime Journal (/run/log/journal/3a8dbab828fc40a183893e468c03e10b) is 1.8M, max 13.8M, 11.9M free. Jul 24 10:26:02.370857 osdx systemd-journald[2180]: Received client request to rotate journal, rotating. Jul 24 10:26:02.370905 osdx systemd-journald[2180]: Vacuuming done, freed 0B of archived journals from /run/log/journal/3a8dbab828fc40a183893e468c03e10b. Jul 24 10:26:02.381706 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal clear'. Jul 24 10:26:02.610635 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system coredump delete all'. Jul 24 10:26:02.868774 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu. Jul 24 10:26:02.970854 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'. Jul 24 10:26:03.042236 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'. Jul 24 10:26:03.165864 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'. Jul 24 10:26:03.281513 osdx ubnt-cfgd[561098]: inactive Jul 24 10:26:03.314425 osdx INFO[561107]: FRR daemons did not change Jul 24 10:26:03.354366 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0 Jul 24 10:26:03.406965 osdx WARNING[561178]: No supported link modes on interface eth0 Jul 24 10:26:03.408711 osdx modulelauncher[561178]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on Jul 24 10:26:03.408726 osdx modulelauncher[561178]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76. Jul 24 10:26:03.410002 osdx modulelauncher[561178]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off -- Jul 24 10:26:03.410014 osdx modulelauncher[561178]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75. Jul 24 10:26:03.624876 osdx cfgd[1923]: [414651]Completed change to active configuration Jul 24 10:26:03.625435 osdx OSDxCLI[414651]: User 'admin' committed the configuration. Jul 24 10:26:03.650477 osdx OSDxCLI[414651]: User 'admin' left the configuration menu. Jul 24 10:26:03.825999 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'. Jul 24 10:26:03.903709 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal show | cat'. Jul 24 10:26:04.073957 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu. Jul 24 10:26:04.144380 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'. Jul 24 10:26:04.247389 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy source RD url http://10.215.168.1/~robot/RD-resolver.md'. Jul 24 10:26:04.325088 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy source RD minisign-key RWQc0jv6ZbtYLlNXRWNMP/aXgCRsmXGZXJJZ38hPCe1//wTsa35BlF9p'. Jul 24 10:26:04.418999 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy source RD prefix PRIVATE-'. Jul 24 10:26:04.474840 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy server-name PRIVATE-rd-server'. Jul 24 10:26:04.604901 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'. Jul 24 10:26:04.677969 osdx ubnt-cfgd[561284]: inactive Jul 24 10:26:04.702227 osdx INFO[561293]: FRR daemons did not change Jul 24 10:26:04.715798 osdx ca-certificates[561309]: Updating certificates in /etc/ssl/certs... Jul 24 10:26:05.374001 osdx ubnt-cfgd[562321]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL Jul 24 10:26:05.385316 osdx ca-certificates[562328]: 1 added, 0 removed; done. Jul 24 10:26:05.389803 osdx ca-certificates[562333]: Running hooks in /etc/ca-certificates/update.d... Jul 24 10:26:05.393874 osdx ca-certificates[562335]: done. Jul 24 10:26:05.475011 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy. Jul 24 10:26:05.489156 osdx cfgd[1923]: [414651]Completed change to active configuration Jul 24 10:26:05.490253 osdx OSDxCLI[414651]: User 'admin' committed the configuration. Jul 24 10:26:05.517013 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] dnscrypt-proxy 2.0.45 Jul 24 10:26:05.517281 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] Network connectivity detected Jul 24 10:26:05.517281 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] Dropping privileges Jul 24 10:26:05.519810 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] Network connectivity detected Jul 24 10:26:05.520034 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] Now listening to 127.0.0.1:53 [UDP] Jul 24 10:26:05.520034 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] Now listening to 127.0.0.1:53 [TCP] Jul 24 10:26:05.527776 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [WARNING] /var/cache/dnscrypt-proxy/RD.md: open /var/cache/dnscrypt-proxy/sf-2fime5c27vzbvnax.tmp: permission denied Jul 24 10:26:05.527776 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] Source [RD] loaded Jul 24 10:26:05.527776 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [WARNING] Missing stamp for server [PRIVATE-server-name`] Jul 24 10:26:05.527776 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [WARNING] Error in source [RD]: [Missing stamp for server [PRIVATE-server-name`]] -- Continuing with reduced server count [1] Jul 24 10:26:05.527776 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] Firefox workaround initialized Jul 24 10:26:05.527776 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] Loading the set of cloaking rules from [/tmp/tmplzlf4ddr] Jul 24 10:26:05.535230 osdx OSDxCLI[414651]: User 'admin' left the configuration menu. Jul 24 10:26:05.663743 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] [PRIVATE-rd-server] OK (DoH) - rtt: 112ms Jul 24 10:26:05.663743 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] Server with the lowest initial latency: PRIVATE-rd-server (rtt: 112ms) Jul 24 10:26:05.663743 osdx dnscrypt-proxy[562339]: [2026-07-24 10:26:05] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Invalid Source
Description
Configures an invalid source with a random minisign key and expects it to fail.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy log level 0 set service dns proxy server-name rd-server set service dns proxy source RD minisign-key PPIZxb3TUwNlvvXWDVKaxfo4 set service dns proxy source RD url 'http://10.215.168.1/~robot/invalid-source' set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Invalid Minisign Key
Description
Configures a valid source but with an incorrect minisign key, which should fail.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.215.168.64/24 set protocols static route 0.0.0.0/0 next-hop 10.215.168.1 set service dns proxy log level 0 set service dns proxy server-name rd-server set service dns proxy source RD minisign-key InvalidMinisignKey== set service dns proxy source RD url 'http://10.215.168.1/~robot/RD-resolver.md' set system certificate trust 'running://remote.dns-server.crt' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'