Cipher

Test suite to validate using one or multiple ciphers to protect DoH connection

Single Valid Cipher

Description

Configures a single, valid cipher and tries to communicate with the server. No refusal of the proposed cipher is expected.

Scenario

Example 1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

Cipher suite: 49199
Show output
Sep 17 00:31:30.337125 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:31:30.338072 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:31:30.338137 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:31:30.352297 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:31:30.704062 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 17 00:31:30.957403 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:31:31.047187 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:31:31.171574 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:31:31.270335 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:31:31.400348 osdx ubnt-cfgd[640801]: inactive
Sep 17 00:31:31.429911 osdx INFO[640812]: FRR daemons did not change
Sep 17 00:31:31.462050 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:31:31.508669 osdx WARNING[640883]: No supported link modes on interface eth0
Sep 17 00:31:31.510017 osdx modulelauncher[640883]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:31:31.510042 osdx modulelauncher[640883]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:31:31.511209 osdx modulelauncher[640883]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:31:31.511216 osdx modulelauncher[640883]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:31:31.743672 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:31:31.744270 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:31:31.776377 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:31:31.941578 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Sep 17 00:31:32.023399 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 17 00:31:32.212411 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:31:32.283377 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:31:32.380980 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:31:32.451657 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:31:32.552524 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:31:32.618281 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:31:32.729001 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256'.
Sep 17 00:31:32.796534 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:31:32.926175 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:31:32.984860 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:31:33.103564 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:31:33.166550 osdx ubnt-cfgd[640998]: inactive
Sep 17 00:31:33.188253 osdx INFO[641007]: FRR daemons did not change
Sep 17 00:31:33.201731 osdx ca-certificates[641022]: Updating certificates in /etc/ssl/certs...
Sep 17 00:31:33.745479 osdx ubnt-cfgd[642035]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:31:33.755604 osdx ca-certificates[642041]: 1 added, 0 removed; done.
Sep 17 00:31:33.758355 osdx ca-certificates[642047]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:31:33.761135 osdx ca-certificates[642049]: done.
Sep 17 00:31:33.838385 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:31:33.847128 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:31:33.847688 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:31:33.861365 osdx dnscrypt-proxy[642053]: dnscrypt-proxy 2.0.45
Sep 17 00:31:33.861432 osdx dnscrypt-proxy[642053]: Network connectivity detected
Sep 17 00:31:33.861648 osdx dnscrypt-proxy[642053]: Dropping privileges
Sep 17 00:31:33.864026 osdx dnscrypt-proxy[642053]: Network connectivity detected
Sep 17 00:31:33.864061 osdx dnscrypt-proxy[642053]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:31:33.864067 osdx dnscrypt-proxy[642053]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:31:33.864087 osdx dnscrypt-proxy[642053]: Firefox workaround initialized
Sep 17 00:31:33.864092 osdx dnscrypt-proxy[642053]: Loading the set of cloaking rules from [/tmp/tmpio8xa7fy]
Sep 17 00:31:33.870619 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:31:34.000498 osdx dnscrypt-proxy[642053]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 49199
Sep 17 00:31:34.000519 osdx dnscrypt-proxy[642053]: [RD] OK (DoH) - rtt: 118ms
Sep 17 00:31:34.000528 osdx dnscrypt-proxy[642053]: Server with the lowest initial latency: RD (rtt: 118ms)
Sep 17 00:31:34.000533 osdx dnscrypt-proxy[642053]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:31:34.029306 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'show host lookup teldat.com type A'.

Multiple Valid Cipher

Description

Configures a valid cipher each time, and tries to communicate with the server. No refusal of the proposed cipher is expected.

Scenario

Example 1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

Cipher suite: 49199
Show output
Sep 17 00:31:42.343362 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:31:42.346171 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:31:42.346263 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:31:42.356312 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:31:42.629121 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 17 00:31:42.945280 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:31:43.062232 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:31:43.161416 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:31:43.229215 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:31:43.386191 osdx ubnt-cfgd[643826]: inactive
Sep 17 00:31:43.411849 osdx INFO[643837]: FRR daemons did not change
Sep 17 00:31:43.438178 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:31:43.488105 osdx WARNING[643908]: No supported link modes on interface eth0
Sep 17 00:31:43.489614 osdx modulelauncher[643908]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:31:43.489631 osdx modulelauncher[643908]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:31:43.490837 osdx modulelauncher[643908]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:31:43.490847 osdx modulelauncher[643908]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:31:43.704646 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:31:43.705302 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:31:43.740502 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:31:43.935848 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Sep 17 00:31:44.015510 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 17 00:31:44.213761 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:31:44.285124 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:31:44.379731 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:31:44.440889 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:31:44.541968 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:31:44.686463 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:31:44.756242 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256'.
Sep 17 00:31:44.868618 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:31:45.006435 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:31:45.070621 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:31:45.184083 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:31:45.255256 osdx ubnt-cfgd[644023]: inactive
Sep 17 00:31:45.289450 osdx INFO[644032]: FRR daemons did not change
Sep 17 00:31:45.304678 osdx ca-certificates[644047]: Updating certificates in /etc/ssl/certs...
Sep 17 00:31:45.943920 osdx ubnt-cfgd[645060]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:31:45.956277 osdx ca-certificates[645067]: 1 added, 0 removed; done.
Sep 17 00:31:45.960533 osdx ca-certificates[645072]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:31:45.966670 osdx ca-certificates[645074]: done.
Sep 17 00:31:46.054591 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:31:46.071854 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:31:46.072841 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:31:46.092849 osdx dnscrypt-proxy[645078]: dnscrypt-proxy 2.0.45
Sep 17 00:31:46.092926 osdx dnscrypt-proxy[645078]: Network connectivity detected
Sep 17 00:31:46.093208 osdx dnscrypt-proxy[645078]: Dropping privileges
Sep 17 00:31:46.095051 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:31:46.098304 osdx dnscrypt-proxy[645078]: Network connectivity detected
Sep 17 00:31:46.098340 osdx dnscrypt-proxy[645078]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:31:46.098345 osdx dnscrypt-proxy[645078]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:31:46.098364 osdx dnscrypt-proxy[645078]: Firefox workaround initialized
Sep 17 00:31:46.098369 osdx dnscrypt-proxy[645078]: Loading the set of cloaking rules from [/tmp/tmp67oaa7qc]
Sep 17 00:31:46.246253 osdx dnscrypt-proxy[645078]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 49199
Sep 17 00:31:46.246273 osdx dnscrypt-proxy[645078]: [RD] OK (DoH) - rtt: 131ms
Sep 17 00:31:46.246284 osdx dnscrypt-proxy[645078]: Server with the lowest initial latency: RD (rtt: 131ms)
Sep 17 00:31:46.246290 osdx dnscrypt-proxy[645078]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:31:46.267035 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'show host lookup teldat.com type A'.

Example 2

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

Cipher suite: 49200
Show output
Sep 17 00:31:46.485296 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:31:46.486162 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:31:46.486219 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:31:46.495645 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:31:46.771449 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:31:46.839588 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'delete '.
Sep 17 00:31:46.973542 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system login user admin authentication plaintext-password ******'.
Sep 17 00:31:47.036626 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:31:47.131993 osdx ubnt-cfgd[645144]: inactive
Sep 17 00:31:47.156231 osdx dnscrypt-proxy[645078]: Stopped.
Sep 17 00:31:47.156304 osdx systemd[1]: Stopping dnscrypt-proxy.service - DNSCrypt client proxy...
Sep 17 00:31:47.157459 osdx systemd[1]: dnscrypt-proxy.service: Deactivated successfully.
Sep 17 00:31:47.157628 osdx systemd[1]: Stopped dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:31:47.219983 osdx WARNING[645210]: No supported link modes on interface eth0
Sep 17 00:31:47.221352 osdx modulelauncher[645210]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:31:47.221366 osdx modulelauncher[645210]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:31:47.222513 osdx modulelauncher[645210]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:31:47.222521 osdx modulelauncher[645210]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:31:47.239467 osdx ca-certificates[645233]: Clearing symlinks in /etc/ssl/certs...
Sep 17 00:31:47.549403 osdx ca-certificates[645810]: done.
Sep 17 00:31:47.553173 osdx ca-certificates[645819]: Updating certificates in /etc/ssl/certs...
Sep 17 00:31:48.094306 osdx ubnt-cfgd[646677]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:31:48.131875 osdx ca-certificates[646684]: 142 added, 0 removed; done.
Sep 17 00:31:48.136100 osdx ca-certificates[646689]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:31:48.139910 osdx ca-certificates[646691]: done.
Sep 17 00:31:48.239871 osdx INFO[646703]: FRR daemons did not change
Sep 17 00:31:48.365427 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:31:48.366150 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:31:48.390386 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:31:49.833319 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:31:49.912670 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:31:50.020526 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:31:50.098627 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:31:50.229158 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:31:50.329219 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:31:50.431467 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384'.
Sep 17 00:31:50.497942 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:31:50.633248 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:31:50.689856 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:31:50.803609 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:31:50.870248 osdx ubnt-cfgd[646758]: inactive
Sep 17 00:31:50.900877 osdx INFO[646771]: FRR daemons did not change
Sep 17 00:31:50.913780 osdx ca-certificates[646787]: Updating certificates in /etc/ssl/certs...
Sep 17 00:31:51.450633 osdx ubnt-cfgd[647799]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:31:51.459653 osdx ca-certificates[647804]: 1 added, 0 removed; done.
Sep 17 00:31:51.462444 osdx ca-certificates[647811]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:31:51.465058 osdx ca-certificates[647813]: done.
Sep 17 00:31:51.494163 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:31:51.542990 osdx WARNING[647882]: No supported link modes on interface eth0
Sep 17 00:31:51.544314 osdx modulelauncher[647882]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:31:51.544329 osdx modulelauncher[647882]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:31:51.545495 osdx modulelauncher[647882]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:31:51.545502 osdx modulelauncher[647882]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:31:51.666565 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:31:51.686354 osdx dnscrypt-proxy[647926]: dnscrypt-proxy 2.0.45
Sep 17 00:31:51.686436 osdx dnscrypt-proxy[647926]: Network connectivity detected
Sep 17 00:31:51.686672 osdx dnscrypt-proxy[647926]: Dropping privileges
Sep 17 00:31:51.688868 osdx dnscrypt-proxy[647926]: Network connectivity detected
Sep 17 00:31:51.688909 osdx dnscrypt-proxy[647926]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:31:51.688913 osdx dnscrypt-proxy[647926]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:31:51.688933 osdx dnscrypt-proxy[647926]: Firefox workaround initialized
Sep 17 00:31:51.688936 osdx dnscrypt-proxy[647926]: Loading the set of cloaking rules from [/tmp/tmpkmzr1huf]
Sep 17 00:31:51.827741 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:31:51.828252 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:31:51.840148 osdx dnscrypt-proxy[647926]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 49200
Sep 17 00:31:51.840166 osdx dnscrypt-proxy[647926]: [RD] OK (DoH) - rtt: 135ms
Sep 17 00:31:51.840175 osdx dnscrypt-proxy[647926]: Server with the lowest initial latency: RD (rtt: 135ms)
Sep 17 00:31:51.840180 osdx dnscrypt-proxy[647926]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:31:51.846305 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:31:52.006431 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'show host lookup teldat.com type A'.

Example 3

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

Cipher suite: 52392
Show output
Sep 17 00:31:52.219042 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:31:52.222159 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:31:52.222216 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:31:52.231837 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:31:52.502527 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:31:52.611108 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'delete '.
Sep 17 00:31:52.703114 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system login user admin authentication plaintext-password ******'.
Sep 17 00:31:52.779651 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:31:52.875356 osdx ubnt-cfgd[648024]: inactive
Sep 17 00:31:52.900732 osdx dnscrypt-proxy[647926]: Stopped.
Sep 17 00:31:52.900849 osdx systemd[1]: Stopping dnscrypt-proxy.service - DNSCrypt client proxy...
Sep 17 00:31:52.901725 osdx systemd[1]: dnscrypt-proxy.service: Deactivated successfully.
Sep 17 00:31:52.901839 osdx systemd[1]: Stopped dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:31:52.964928 osdx WARNING[648090]: No supported link modes on interface eth0
Sep 17 00:31:52.966509 osdx modulelauncher[648090]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:31:52.966526 osdx modulelauncher[648090]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:31:52.967721 osdx modulelauncher[648090]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:31:52.967728 osdx modulelauncher[648090]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:31:52.985423 osdx ca-certificates[648112]: Clearing symlinks in /etc/ssl/certs...
Sep 17 00:31:53.292390 osdx ca-certificates[648689]: done.
Sep 17 00:31:53.296483 osdx ca-certificates[648698]: Updating certificates in /etc/ssl/certs...
Sep 17 00:31:53.876968 osdx ubnt-cfgd[649556]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:31:53.888053 osdx ca-certificates[649562]: 142 added, 0 removed; done.
Sep 17 00:31:53.891915 osdx ca-certificates[649568]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:31:53.895597 osdx ca-certificates[649570]: done.
Sep 17 00:31:53.953246 osdx INFO[649582]: FRR daemons did not change
Sep 17 00:31:54.068456 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:31:54.069049 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:31:54.086867 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:31:55.514518 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:31:55.599186 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:31:55.701835 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:31:55.770856 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:31:55.891352 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:31:55.997505 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:31:56.089150 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256'.
Sep 17 00:31:56.142176 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:31:56.284525 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:31:56.374457 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:31:56.507764 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:31:56.592588 osdx ubnt-cfgd[649636]: inactive
Sep 17 00:31:56.625968 osdx INFO[649649]: FRR daemons did not change
Sep 17 00:31:56.639713 osdx ca-certificates[649665]: Updating certificates in /etc/ssl/certs...
Sep 17 00:31:57.204139 osdx ubnt-cfgd[650677]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:31:57.212326 osdx ca-certificates[650682]: 1 added, 0 removed; done.
Sep 17 00:31:57.216161 osdx ca-certificates[650689]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:31:57.219841 osdx ca-certificates[650691]: done.
Sep 17 00:31:57.250158 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:31:57.297457 osdx WARNING[650760]: No supported link modes on interface eth0
Sep 17 00:31:57.298821 osdx modulelauncher[650760]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:31:57.298834 osdx modulelauncher[650760]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:31:57.299954 osdx modulelauncher[650760]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:31:57.299962 osdx modulelauncher[650760]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:31:57.418449 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:31:57.445128 osdx dnscrypt-proxy[650804]: dnscrypt-proxy 2.0.45
Sep 17 00:31:57.445197 osdx dnscrypt-proxy[650804]: Network connectivity detected
Sep 17 00:31:57.445449 osdx dnscrypt-proxy[650804]: Dropping privileges
Sep 17 00:31:57.447464 osdx dnscrypt-proxy[650804]: Network connectivity detected
Sep 17 00:31:57.447497 osdx dnscrypt-proxy[650804]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:31:57.447502 osdx dnscrypt-proxy[650804]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:31:57.447523 osdx dnscrypt-proxy[650804]: Firefox workaround initialized
Sep 17 00:31:57.447528 osdx dnscrypt-proxy[650804]: Loading the set of cloaking rules from [/tmp/tmpe26du_6g]
Sep 17 00:31:57.595988 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:31:57.596513 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:31:57.600820 osdx dnscrypt-proxy[650804]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 52392
Sep 17 00:31:57.600838 osdx dnscrypt-proxy[650804]: [RD] OK (DoH) - rtt: 135ms
Sep 17 00:31:57.600846 osdx dnscrypt-proxy[650804]: Server with the lowest initial latency: RD (rtt: 135ms)
Sep 17 00:31:57.600851 osdx dnscrypt-proxy[650804]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:31:57.620282 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:31:57.772169 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'show host lookup teldat.com type A'.

Single Invalid Cipher

Description

Configures a single, invalid cipher and tries to communicate with the server. A refusal of the proposed cipher is expected.

Scenario

Example 1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

TLS handshake failure - Try changing or deleting the tls_cipher_suite value in the configuration file
Show output
Sep 17 00:32:06.328594 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:32:06.330733 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:32:06.330801 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:32:06.339626 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:32:06.562836 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 17 00:32:06.818794 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:32:06.905996 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:32:06.986517 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:32:07.113343 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:32:07.174474 osdx ubnt-cfgd[652609]: inactive
Sep 17 00:32:07.204574 osdx INFO[652620]: FRR daemons did not change
Sep 17 00:32:07.238728 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:32:07.288217 osdx WARNING[652691]: No supported link modes on interface eth0
Sep 17 00:32:07.289987 osdx modulelauncher[652691]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:32:07.290003 osdx modulelauncher[652691]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:32:07.291431 osdx modulelauncher[652691]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:32:07.291447 osdx modulelauncher[652691]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:32:07.512550 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:32:07.513086 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:32:07.530505 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:32:07.669951 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Sep 17 00:32:07.746266 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 17 00:32:07.918482 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:32:07.977215 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:32:08.083463 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:32:08.152320 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:32:08.257814 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:32:08.421487 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:32:08.515419 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA'.
Sep 17 00:32:08.592169 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:32:08.704748 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:32:08.794959 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:32:08.907972 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:32:09.003370 osdx ubnt-cfgd[652806]: inactive
Sep 17 00:32:09.043177 osdx INFO[652815]: FRR daemons did not change
Sep 17 00:32:09.062694 osdx ca-certificates[652833]: Updating certificates in /etc/ssl/certs...
Sep 17 00:32:09.929569 osdx ubnt-cfgd[653843]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:32:09.941241 osdx ca-certificates[653849]: 1 added, 0 removed; done.
Sep 17 00:32:09.944605 osdx ca-certificates[653855]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:32:09.948505 osdx ca-certificates[653857]: done.
Sep 17 00:32:10.023097 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:32:10.033285 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:32:10.033894 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:32:10.050758 osdx dnscrypt-proxy[653861]: dnscrypt-proxy 2.0.45
Sep 17 00:32:10.050836 osdx dnscrypt-proxy[653861]: Network connectivity detected
Sep 17 00:32:10.051164 osdx dnscrypt-proxy[653861]: Dropping privileges
Sep 17 00:32:10.053944 osdx dnscrypt-proxy[653861]: Network connectivity detected
Sep 17 00:32:10.053976 osdx dnscrypt-proxy[653861]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:32:10.053980 osdx dnscrypt-proxy[653861]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:32:10.054001 osdx dnscrypt-proxy[653861]: Firefox workaround initialized
Sep 17 00:32:10.054006 osdx dnscrypt-proxy[653861]: Loading the set of cloaking rules from [/tmp/tmpr4_0iygo]
Sep 17 00:32:10.054942 osdx dnscrypt-proxy[653861]: TLS handshake failure - Try changing or deleting the tls_cipher_suite value in the configuration file
Sep 17 00:32:10.064870 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:32:10.189356 osdx dnscrypt-proxy[653861]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 52392
Sep 17 00:32:10.189378 osdx dnscrypt-proxy[653861]: [RD] OK (DoH) - rtt: 109ms
Sep 17 00:32:10.189388 osdx dnscrypt-proxy[653861]: Server with the lowest initial latency: RD (rtt: 109ms)
Sep 17 00:32:10.189394 osdx dnscrypt-proxy[653861]: dnscrypt-proxy is ready - live servers: 1

Multiple Invalid Cipher

Description

Configures either one or two invalid ciphers and tries to communicate with the server. A refusal of all proposed ciphers is expected.

Scenario

Example 1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

TLS handshake failure - Try changing or deleting the tls_cipher_suite value in the configuration file
Show output
Sep 17 00:32:19.318751 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:32:19.320371 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:32:19.320439 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:32:19.331613 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:32:19.634957 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 17 00:32:19.959085 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:32:20.108236 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:32:20.191343 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:32:20.317236 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:32:20.424319 osdx ubnt-cfgd[655631]: inactive
Sep 17 00:32:20.449499 osdx INFO[655642]: FRR daemons did not change
Sep 17 00:32:20.480388 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:32:20.530194 osdx WARNING[655713]: No supported link modes on interface eth0
Sep 17 00:32:20.531706 osdx modulelauncher[655713]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:32:20.531719 osdx modulelauncher[655713]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:32:20.532973 osdx modulelauncher[655713]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:32:20.532980 osdx modulelauncher[655713]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:32:20.758376 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:32:20.758964 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:32:20.778490 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:32:20.926448 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Sep 17 00:32:21.003413 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 17 00:32:21.208378 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:32:21.276469 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:32:21.419844 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:32:21.488542 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:32:21.580601 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:32:21.696487 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:32:21.777803 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA'.
Sep 17 00:32:21.882785 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:32:21.979441 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:32:22.071470 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:32:22.166436 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:32:22.332545 osdx ubnt-cfgd[655828]: inactive
Sep 17 00:32:22.380352 osdx INFO[655837]: FRR daemons did not change
Sep 17 00:32:22.395273 osdx ca-certificates[655853]: Updating certificates in /etc/ssl/certs...
Sep 17 00:32:23.072851 osdx ubnt-cfgd[656865]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:32:23.083990 osdx ca-certificates[656871]: 1 added, 0 removed; done.
Sep 17 00:32:23.088165 osdx ca-certificates[656877]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:32:23.092097 osdx ca-certificates[656879]: done.
Sep 17 00:32:23.164842 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:32:23.178203 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:32:23.178883 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:32:23.195678 osdx dnscrypt-proxy[656883]: dnscrypt-proxy 2.0.45
Sep 17 00:32:23.195766 osdx dnscrypt-proxy[656883]: Network connectivity detected
Sep 17 00:32:23.196003 osdx dnscrypt-proxy[656883]: Dropping privileges
Sep 17 00:32:23.198273 osdx dnscrypt-proxy[656883]: Network connectivity detected
Sep 17 00:32:23.198306 osdx dnscrypt-proxy[656883]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:32:23.198326 osdx dnscrypt-proxy[656883]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:32:23.198344 osdx dnscrypt-proxy[656883]: Firefox workaround initialized
Sep 17 00:32:23.198352 osdx dnscrypt-proxy[656883]: Loading the set of cloaking rules from [/tmp/tmpl3pqdy4u]
Sep 17 00:32:23.199798 osdx dnscrypt-proxy[656883]: TLS handshake failure - Try changing or deleting the tls_cipher_suite value in the configuration file
Sep 17 00:32:23.210512 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:32:23.334772 osdx dnscrypt-proxy[656883]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 52392
Sep 17 00:32:23.334795 osdx dnscrypt-proxy[656883]: [RD] OK (DoH) - rtt: 116ms
Sep 17 00:32:23.334805 osdx dnscrypt-proxy[656883]: Server with the lowest initial latency: RD (rtt: 116ms)
Sep 17 00:32:23.334810 osdx dnscrypt-proxy[656883]: dnscrypt-proxy is ready - live servers: 1

Example 2

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_RSA_WITH_3DES_EDE_CBC_SHA
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

TLS handshake failure - Try changing or deleting the tls_cipher_suite value in the configuration file
Show output
Sep 17 00:32:23.561651 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:32:23.565112 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:32:23.565182 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:32:23.573635 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:32:23.916094 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:32:24.015065 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'delete '.
Sep 17 00:32:24.182764 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system login user admin authentication plaintext-password ******'.
Sep 17 00:32:24.271794 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:32:24.420613 osdx ubnt-cfgd[656945]: inactive
Sep 17 00:32:24.445562 osdx dnscrypt-proxy[656883]: Stopped.
Sep 17 00:32:24.445607 osdx systemd[1]: Stopping dnscrypt-proxy.service - DNSCrypt client proxy...
Sep 17 00:32:24.446772 osdx systemd[1]: dnscrypt-proxy.service: Deactivated successfully.
Sep 17 00:32:24.446913 osdx systemd[1]: Stopped dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:32:24.517389 osdx WARNING[657011]: No supported link modes on interface eth0
Sep 17 00:32:24.519073 osdx modulelauncher[657011]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:32:24.519092 osdx modulelauncher[657011]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:32:24.520808 osdx modulelauncher[657011]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:32:24.520817 osdx modulelauncher[657011]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:32:24.546476 osdx ca-certificates[657033]: Clearing symlinks in /etc/ssl/certs...
Sep 17 00:32:24.999505 osdx ca-certificates[657611]: done.
Sep 17 00:32:25.007247 osdx ca-certificates[657619]: Updating certificates in /etc/ssl/certs...
Sep 17 00:32:25.676367 osdx ubnt-cfgd[658477]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:32:25.685320 osdx ca-certificates[658482]: 142 added, 0 removed; done.
Sep 17 00:32:25.688384 osdx ca-certificates[658489]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:32:25.691360 osdx ca-certificates[658491]: done.
Sep 17 00:32:25.745317 osdx INFO[658503]: FRR daemons did not change
Sep 17 00:32:25.846824 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:32:25.847430 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:32:25.866119 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:32:27.289503 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:32:27.358356 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:32:27.467223 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:32:27.551722 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:32:27.674093 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:32:27.768425 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:32:27.879981 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_RSA_WITH_3DES_EDE_CBC_SHA'.
Sep 17 00:32:27.956199 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:32:28.122536 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:32:28.187783 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:32:28.318807 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:32:28.395792 osdx ubnt-cfgd[658557]: inactive
Sep 17 00:32:28.430306 osdx INFO[658570]: FRR daemons did not change
Sep 17 00:32:28.444373 osdx ca-certificates[658586]: Updating certificates in /etc/ssl/certs...
Sep 17 00:32:29.024155 osdx ubnt-cfgd[659598]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:32:29.035633 osdx ca-certificates[659604]: 1 added, 0 removed; done.
Sep 17 00:32:29.038811 osdx ca-certificates[659609]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:32:29.041842 osdx ca-certificates[659612]: done.
Sep 17 00:32:29.072435 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:32:29.123589 osdx WARNING[659681]: No supported link modes on interface eth0
Sep 17 00:32:29.125032 osdx modulelauncher[659681]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:32:29.125045 osdx modulelauncher[659681]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:32:29.126219 osdx modulelauncher[659681]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:32:29.126227 osdx modulelauncher[659681]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:32:29.240892 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:32:29.265396 osdx dnscrypt-proxy[659725]: dnscrypt-proxy 2.0.45
Sep 17 00:32:29.265470 osdx dnscrypt-proxy[659725]: Network connectivity detected
Sep 17 00:32:29.265785 osdx dnscrypt-proxy[659725]: Dropping privileges
Sep 17 00:32:29.268872 osdx dnscrypt-proxy[659725]: Network connectivity detected
Sep 17 00:32:29.269139 osdx dnscrypt-proxy[659725]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:32:29.269144 osdx dnscrypt-proxy[659725]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:32:29.269285 osdx dnscrypt-proxy[659725]: Firefox workaround initialized
Sep 17 00:32:29.269292 osdx dnscrypt-proxy[659725]: Loading the set of cloaking rules from [/tmp/tmpny90jfkr]
Sep 17 00:32:29.270686 osdx dnscrypt-proxy[659725]: TLS handshake failure - Try changing or deleting the tls_cipher_suite value in the configuration file
Sep 17 00:32:29.408477 osdx dnscrypt-proxy[659725]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 52392
Sep 17 00:32:29.408491 osdx dnscrypt-proxy[659725]: [RD] OK (DoH) - rtt: 119ms
Sep 17 00:32:29.408499 osdx dnscrypt-proxy[659725]: Server with the lowest initial latency: RD (rtt: 119ms)
Sep 17 00:32:29.408503 osdx dnscrypt-proxy[659725]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:32:29.421627 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:32:29.422232 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:32:29.451172 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.

Example 3

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA
set service dns proxy cipher 2 algorithm TLS_RSA_WITH_3DES_EDE_CBC_SHA
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

TLS handshake failure - Try changing or deleting the tls_cipher_suite value in the configuration file
Show output
Sep 17 00:32:29.732833 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:32:29.736356 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:32:29.736421 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:32:29.742772 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:32:30.077876 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:32:30.182134 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'delete '.
Sep 17 00:32:30.322883 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system login user admin authentication plaintext-password ******'.
Sep 17 00:32:30.389104 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:32:30.512609 osdx ubnt-cfgd[659819]: inactive
Sep 17 00:32:30.540221 osdx dnscrypt-proxy[659725]: Stopped.
Sep 17 00:32:30.540268 osdx systemd[1]: Stopping dnscrypt-proxy.service - DNSCrypt client proxy...
Sep 17 00:32:30.541549 osdx systemd[1]: dnscrypt-proxy.service: Deactivated successfully.
Sep 17 00:32:30.541694 osdx systemd[1]: Stopped dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:32:30.606571 osdx WARNING[659885]: No supported link modes on interface eth0
Sep 17 00:32:30.607952 osdx modulelauncher[659885]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:32:30.607966 osdx modulelauncher[659885]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:32:30.609354 osdx modulelauncher[659885]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:32:30.609362 osdx modulelauncher[659885]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:32:30.628398 osdx ca-certificates[659907]: Clearing symlinks in /etc/ssl/certs...
Sep 17 00:32:30.979072 osdx ca-certificates[660484]: done.
Sep 17 00:32:30.982354 osdx ca-certificates[660493]: Updating certificates in /etc/ssl/certs...
Sep 17 00:32:31.453675 osdx ubnt-cfgd[661351]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:32:31.464209 osdx ca-certificates[661357]: 142 added, 0 removed; done.
Sep 17 00:32:31.467839 osdx ca-certificates[661363]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:32:31.470605 osdx ca-certificates[661365]: done.
Sep 17 00:32:31.517475 osdx INFO[661377]: FRR daemons did not change
Sep 17 00:32:31.625563 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:32:31.626924 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:32:31.659892 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:32:32.946343 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:32:33.008697 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:32:33.109095 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:32:33.173795 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:32:33.327770 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:32:33.450809 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:32:33.542009 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA'.
Sep 17 00:32:33.637922 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 2 algorithm TLS_RSA_WITH_3DES_EDE_CBC_SHA'.
Sep 17 00:32:33.725479 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:32:33.882303 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:32:33.944632 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:32:34.055651 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:32:34.125058 osdx ubnt-cfgd[661432]: inactive
Sep 17 00:32:34.157937 osdx INFO[661445]: FRR daemons did not change
Sep 17 00:32:34.172968 osdx ca-certificates[661460]: Updating certificates in /etc/ssl/certs...
Sep 17 00:32:34.719380 osdx ubnt-cfgd[662473]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:32:34.729778 osdx ca-certificates[662478]: 1 added, 0 removed; done.
Sep 17 00:32:34.733370 osdx ca-certificates[662485]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:32:34.736648 osdx ca-certificates[662487]: done.
Sep 17 00:32:34.772385 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:32:34.827832 osdx WARNING[662556]: No supported link modes on interface eth0
Sep 17 00:32:34.829402 osdx modulelauncher[662556]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:32:34.829417 osdx modulelauncher[662556]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:32:34.830979 osdx modulelauncher[662556]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:32:34.830989 osdx modulelauncher[662556]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:32:34.952835 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:32:34.974071 osdx dnscrypt-proxy[662600]: dnscrypt-proxy 2.0.45
Sep 17 00:32:34.974150 osdx dnscrypt-proxy[662600]: Network connectivity detected
Sep 17 00:32:34.974386 osdx dnscrypt-proxy[662600]: Dropping privileges
Sep 17 00:32:34.979027 osdx dnscrypt-proxy[662600]: Network connectivity detected
Sep 17 00:32:34.979066 osdx dnscrypt-proxy[662600]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:32:34.979071 osdx dnscrypt-proxy[662600]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:32:34.979092 osdx dnscrypt-proxy[662600]: Firefox workaround initialized
Sep 17 00:32:34.979099 osdx dnscrypt-proxy[662600]: Loading the set of cloaking rules from [/tmp/tmp49tdma6l]
Sep 17 00:32:34.980266 osdx dnscrypt-proxy[662600]: TLS handshake failure - Try changing or deleting the tls_cipher_suite value in the configuration file
Sep 17 00:32:35.124513 osdx dnscrypt-proxy[662600]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 52392
Sep 17 00:32:35.124536 osdx dnscrypt-proxy[662600]: [RD] OK (DoH) - rtt: 120ms
Sep 17 00:32:35.124545 osdx dnscrypt-proxy[662600]: Server with the lowest initial latency: RD (rtt: 120ms)
Sep 17 00:32:35.124550 osdx dnscrypt-proxy[662600]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:32:35.139767 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:32:35.140665 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:32:35.165006 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.

Invalid Cipher With Fallback

Description

Configures an invalid cipher and a valid fallback one. It then tries to communicate with the server. No refusal of the cipher is expected, as long as the valid one proposed is used.

Scenario

Example 1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA
set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

Cipher suite: 49199
Show output
Sep 17 00:32:43.364236 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:32:43.366501 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:32:43.366576 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:32:43.376298 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:32:43.594106 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 17 00:32:43.850394 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:32:43.978395 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:32:44.052722 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:32:44.169738 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:32:44.229929 osdx ubnt-cfgd[664401]: inactive
Sep 17 00:32:44.258205 osdx INFO[664412]: FRR daemons did not change
Sep 17 00:32:44.290539 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:32:44.343884 osdx WARNING[664483]: No supported link modes on interface eth0
Sep 17 00:32:44.345362 osdx modulelauncher[664483]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:32:44.345380 osdx modulelauncher[664483]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:32:44.346577 osdx modulelauncher[664483]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:32:44.346586 osdx modulelauncher[664483]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:32:44.576174 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:32:44.576714 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:32:44.598978 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:32:44.763866 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Sep 17 00:32:44.831281 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 17 00:32:44.966830 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:32:45.617809 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:32:45.678240 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:32:45.780852 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:32:45.842379 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:32:45.957007 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:32:46.011923 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA'.
Sep 17 00:32:46.116179 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256'.
Sep 17 00:32:46.173389 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:32:46.307753 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:32:46.371889 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:32:46.498957 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:32:46.591655 osdx ubnt-cfgd[664599]: inactive
Sep 17 00:32:46.614858 osdx INFO[664608]: FRR daemons did not change
Sep 17 00:32:46.628922 osdx ca-certificates[664624]: Updating certificates in /etc/ssl/certs...
Sep 17 00:32:47.252682 osdx ubnt-cfgd[665636]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:32:47.260572 osdx ca-certificates[665642]: 1 added, 0 removed; done.
Sep 17 00:32:47.263610 osdx ca-certificates[665648]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:32:47.266541 osdx ca-certificates[665650]: done.
Sep 17 00:32:47.342898 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:32:47.352208 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:32:47.352766 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:32:47.369143 osdx dnscrypt-proxy[665654]: dnscrypt-proxy 2.0.45
Sep 17 00:32:47.369547 osdx dnscrypt-proxy[665654]: Network connectivity detected
Sep 17 00:32:47.369798 osdx dnscrypt-proxy[665654]: Dropping privileges
Sep 17 00:32:47.372668 osdx dnscrypt-proxy[665654]: Network connectivity detected
Sep 17 00:32:47.372705 osdx dnscrypt-proxy[665654]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:32:47.372711 osdx dnscrypt-proxy[665654]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:32:47.372734 osdx dnscrypt-proxy[665654]: Firefox workaround initialized
Sep 17 00:32:47.372741 osdx dnscrypt-proxy[665654]: Loading the set of cloaking rules from [/tmp/tmpykajutw0]
Sep 17 00:32:47.378591 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:32:47.533711 osdx dnscrypt-proxy[665654]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 49199
Sep 17 00:32:47.533725 osdx dnscrypt-proxy[665654]: [RD] OK (DoH) - rtt: 140ms
Sep 17 00:32:47.533733 osdx dnscrypt-proxy[665654]: Server with the lowest initial latency: RD (rtt: 140ms)
Sep 17 00:32:47.533738 osdx dnscrypt-proxy[665654]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:32:52.547125 osdx OSDxCLI[538347]: User 'admin' entered an invalid command: 'show host lookup teldat.com type A'.
Sep 17 00:33:02.644742 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'show host lookup teldat.com type A'.

Example 2

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA
set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

Cipher suite: 49200
Show output
Sep 17 00:33:02.844631 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:33:02.846494 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:33:02.846561 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:33:02.857738 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:33:03.122242 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:33:03.178423 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'delete '.
Sep 17 00:33:03.295640 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system login user admin authentication plaintext-password ******'.
Sep 17 00:33:03.354906 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:33:03.444119 osdx ubnt-cfgd[665724]: inactive
Sep 17 00:33:03.471726 osdx systemd[1]: Stopping dnscrypt-proxy.service - DNSCrypt client proxy...
Sep 17 00:33:03.471977 osdx dnscrypt-proxy[665654]: Stopped.
Sep 17 00:33:03.472997 osdx systemd[1]: dnscrypt-proxy.service: Deactivated successfully.
Sep 17 00:33:03.473108 osdx systemd[1]: Stopped dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:33:03.530665 osdx WARNING[665790]: No supported link modes on interface eth0
Sep 17 00:33:03.532128 osdx modulelauncher[665790]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:33:03.532141 osdx modulelauncher[665790]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:33:03.533355 osdx modulelauncher[665790]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:33:03.533363 osdx modulelauncher[665790]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:33:03.550042 osdx ca-certificates[665812]: Clearing symlinks in /etc/ssl/certs...
Sep 17 00:33:03.830125 osdx ca-certificates[666389]: done.
Sep 17 00:33:03.833282 osdx ca-certificates[666398]: Updating certificates in /etc/ssl/certs...
Sep 17 00:33:04.353913 osdx ubnt-cfgd[667256]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:33:04.364214 osdx ca-certificates[667261]: 142 added, 0 removed; done.
Sep 17 00:33:04.368323 osdx ca-certificates[667268]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:33:04.372660 osdx ca-certificates[667270]: done.
Sep 17 00:33:04.426445 osdx INFO[667282]: FRR daemons did not change
Sep 17 00:33:04.553066 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:33:04.553664 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:33:04.578194 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:33:06.289639 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:33:07.073864 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:33:07.194924 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:33:07.320362 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:33:07.443531 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:33:07.562739 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:33:07.685326 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA'.
Sep 17 00:33:07.782407 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384'.
Sep 17 00:33:07.908838 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:33:08.049782 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:33:08.133440 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:33:08.286525 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:33:08.377733 osdx ubnt-cfgd[667337]: inactive
Sep 17 00:33:08.411531 osdx INFO[667350]: FRR daemons did not change
Sep 17 00:33:08.430418 osdx ca-certificates[667366]: Updating certificates in /etc/ssl/certs...
Sep 17 00:33:09.114176 osdx ubnt-cfgd[668378]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:33:09.125536 osdx ca-certificates[668383]: 1 added, 0 removed; done.
Sep 17 00:33:09.129075 osdx ca-certificates[668390]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:33:09.133099 osdx ca-certificates[668392]: done.
Sep 17 00:33:09.170510 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:33:09.227288 osdx WARNING[668461]: No supported link modes on interface eth0
Sep 17 00:33:09.228656 osdx modulelauncher[668461]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:33:09.228671 osdx modulelauncher[668461]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:33:09.230147 osdx modulelauncher[668461]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:33:09.230154 osdx modulelauncher[668461]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:33:09.355780 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:33:09.383725 osdx dnscrypt-proxy[668505]: dnscrypt-proxy 2.0.45
Sep 17 00:33:09.383850 osdx dnscrypt-proxy[668505]: Network connectivity detected
Sep 17 00:33:09.384101 osdx dnscrypt-proxy[668505]: Dropping privileges
Sep 17 00:33:09.388112 osdx dnscrypt-proxy[668505]: Network connectivity detected
Sep 17 00:33:09.388147 osdx dnscrypt-proxy[668505]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:33:09.388152 osdx dnscrypt-proxy[668505]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:33:09.388172 osdx dnscrypt-proxy[668505]: Firefox workaround initialized
Sep 17 00:33:09.388178 osdx dnscrypt-proxy[668505]: Loading the set of cloaking rules from [/tmp/tmp_ysfjj2c]
Sep 17 00:33:09.537792 osdx dnscrypt-proxy[668505]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 49200
Sep 17 00:33:09.537811 osdx dnscrypt-proxy[668505]: [RD] OK (DoH) - rtt: 127ms
Sep 17 00:33:09.537818 osdx dnscrypt-proxy[668505]: Server with the lowest initial latency: RD (rtt: 127ms)
Sep 17 00:33:09.537822 osdx dnscrypt-proxy[668505]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:33:09.564371 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:33:09.565026 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:33:09.584075 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:33:09.740186 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'show host lookup teldat.com type A'.

Example 3

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA
set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

Cipher suite: 52392
Show output
Sep 17 00:33:09.985960 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:33:09.986549 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:33:09.986591 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:33:10.001170 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:33:10.407952 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:33:10.523569 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'delete '.
Sep 17 00:33:10.654171 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system login user admin authentication plaintext-password ******'.
Sep 17 00:33:10.753814 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:33:10.820006 osdx ubnt-cfgd[668602]: inactive
Sep 17 00:33:10.846418 osdx dnscrypt-proxy[668505]: Stopped.
Sep 17 00:33:10.846448 osdx systemd[1]: Stopping dnscrypt-proxy.service - DNSCrypt client proxy...
Sep 17 00:33:10.847859 osdx systemd[1]: dnscrypt-proxy.service: Deactivated successfully.
Sep 17 00:33:10.847992 osdx systemd[1]: Stopped dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:33:10.914751 osdx WARNING[668668]: No supported link modes on interface eth0
Sep 17 00:33:10.916150 osdx modulelauncher[668668]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:33:10.916164 osdx modulelauncher[668668]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:33:10.917304 osdx modulelauncher[668668]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:33:10.917311 osdx modulelauncher[668668]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:33:10.937075 osdx ca-certificates[668690]: Clearing symlinks in /etc/ssl/certs...
Sep 17 00:33:11.238688 osdx ca-certificates[669267]: done.
Sep 17 00:33:11.241534 osdx ca-certificates[669275]: Updating certificates in /etc/ssl/certs...
Sep 17 00:33:11.726554 osdx ubnt-cfgd[670134]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:33:11.735287 osdx ca-certificates[670139]: 142 added, 0 removed; done.
Sep 17 00:33:11.738680 osdx ca-certificates[670146]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:33:11.741806 osdx ca-certificates[670148]: done.
Sep 17 00:33:11.794539 osdx INFO[670160]: FRR daemons did not change
Sep 17 00:33:11.891619 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:33:11.892154 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:33:11.907194 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:33:13.030871 osdx systemd[1]: systemd-timedated.service: Deactivated successfully.
Sep 17 00:33:13.246771 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:33:13.935825 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:33:14.002039 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:33:14.104544 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:33:14.161564 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:33:14.258642 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:33:14.323747 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_RSA_WITH_RC4_128_SHA'.
Sep 17 00:33:14.431519 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256'.
Sep 17 00:33:14.498443 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:33:14.624147 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:33:14.677461 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:33:14.797389 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:33:14.872170 osdx ubnt-cfgd[670217]: inactive
Sep 17 00:33:14.903287 osdx INFO[670230]: FRR daemons did not change
Sep 17 00:33:14.917251 osdx ca-certificates[670246]: Updating certificates in /etc/ssl/certs...
Sep 17 00:33:15.459884 osdx ubnt-cfgd[671258]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:33:15.467714 osdx ca-certificates[671263]: 1 added, 0 removed; done.
Sep 17 00:33:15.470498 osdx ca-certificates[671270]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:33:15.473181 osdx ca-certificates[671272]: done.
Sep 17 00:33:15.502498 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:33:15.547611 osdx WARNING[671341]: No supported link modes on interface eth0
Sep 17 00:33:15.549043 osdx modulelauncher[671341]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:33:15.549058 osdx modulelauncher[671341]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:33:15.550192 osdx modulelauncher[671341]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:33:15.550200 osdx modulelauncher[671341]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:33:15.662858 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:33:15.683362 osdx dnscrypt-proxy[671385]: dnscrypt-proxy 2.0.45
Sep 17 00:33:15.683435 osdx dnscrypt-proxy[671385]: Network connectivity detected
Sep 17 00:33:15.683649 osdx dnscrypt-proxy[671385]: Dropping privileges
Sep 17 00:33:15.685668 osdx dnscrypt-proxy[671385]: Network connectivity detected
Sep 17 00:33:15.685697 osdx dnscrypt-proxy[671385]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:33:15.685701 osdx dnscrypt-proxy[671385]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:33:15.685713 osdx dnscrypt-proxy[671385]: Firefox workaround initialized
Sep 17 00:33:15.685718 osdx dnscrypt-proxy[671385]: Loading the set of cloaking rules from [/tmp/tmpf4flm52f]
Sep 17 00:33:15.839779 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:33:15.840287 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:33:15.856604 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:33:16.026967 osdx dnscrypt-proxy[671385]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 52392
Sep 17 00:33:16.026993 osdx dnscrypt-proxy[671385]: [RD] OK (DoH) - rtt: 321ms
Sep 17 00:33:16.027003 osdx dnscrypt-proxy[671385]: Server with the lowest initial latency: RD (rtt: 321ms)
Sep 17 00:33:16.027011 osdx dnscrypt-proxy[671385]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:33:21.001808 osdx OSDxCLI[538347]: User 'admin' entered an invalid command: 'show host lookup teldat.com type A'.
Sep 17 00:33:31.101294 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'show host lookup teldat.com type A'.

Example 4

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_RSA_WITH_3DES_EDE_CBC_SHA
set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

Cipher suite: 49199
Show output
Sep 17 00:33:31.327547 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:33:31.330537 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:33:31.330603 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:33:31.339891 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:33:31.629497 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:33:31.694973 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'delete '.
Sep 17 00:33:31.807781 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system login user admin authentication plaintext-password ******'.
Sep 17 00:33:31.874758 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:33:31.968363 osdx ubnt-cfgd[671486]: inactive
Sep 17 00:33:31.992896 osdx dnscrypt-proxy[671385]: Stopped.
Sep 17 00:33:31.993022 osdx systemd[1]: Stopping dnscrypt-proxy.service - DNSCrypt client proxy...
Sep 17 00:33:31.994179 osdx systemd[1]: dnscrypt-proxy.service: Deactivated successfully.
Sep 17 00:33:31.994323 osdx systemd[1]: Stopped dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:33:32.062179 osdx WARNING[671552]: No supported link modes on interface eth0
Sep 17 00:33:32.063914 osdx modulelauncher[671552]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:33:32.063928 osdx modulelauncher[671552]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:33:32.065234 osdx modulelauncher[671552]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:33:32.065244 osdx modulelauncher[671552]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:33:32.084572 osdx ca-certificates[671574]: Clearing symlinks in /etc/ssl/certs...
Sep 17 00:33:32.379386 osdx ca-certificates[672152]: done.
Sep 17 00:33:32.382357 osdx ca-certificates[672161]: Updating certificates in /etc/ssl/certs...
Sep 17 00:33:32.870447 osdx ubnt-cfgd[673018]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:33:32.878798 osdx ca-certificates[673023]: 142 added, 0 removed; done.
Sep 17 00:33:32.881765 osdx ca-certificates[673030]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:33:32.884474 osdx ca-certificates[673032]: done.
Sep 17 00:33:32.933937 osdx INFO[673044]: FRR daemons did not change
Sep 17 00:33:33.052256 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:33:33.052808 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:33:33.073288 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:33:34.290087 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:33:35.014523 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:33:35.084723 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:33:35.188500 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:33:35.245200 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:33:35.357028 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:33:35.417350 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_RSA_WITH_3DES_EDE_CBC_SHA'.
Sep 17 00:33:35.506522 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256'.
Sep 17 00:33:35.557941 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:33:35.694186 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:33:35.754676 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:33:35.880208 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:33:35.984941 osdx ubnt-cfgd[673099]: inactive
Sep 17 00:33:36.014889 osdx INFO[673112]: FRR daemons did not change
Sep 17 00:33:36.027705 osdx ca-certificates[673128]: Updating certificates in /etc/ssl/certs...
Sep 17 00:33:36.562293 osdx ubnt-cfgd[674140]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:33:36.570339 osdx ca-certificates[674146]: 1 added, 0 removed; done.
Sep 17 00:33:36.573149 osdx ca-certificates[674152]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:33:36.576772 osdx ca-certificates[674154]: done.
Sep 17 00:33:36.610499 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:33:36.662460 osdx WARNING[674223]: No supported link modes on interface eth0
Sep 17 00:33:36.664102 osdx modulelauncher[674223]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:33:36.664117 osdx modulelauncher[674223]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:33:36.665541 osdx modulelauncher[674223]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:33:36.665549 osdx modulelauncher[674223]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:33:36.774895 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:33:36.802898 osdx dnscrypt-proxy[674267]: dnscrypt-proxy 2.0.45
Sep 17 00:33:36.802974 osdx dnscrypt-proxy[674267]: Network connectivity detected
Sep 17 00:33:36.803188 osdx dnscrypt-proxy[674267]: Dropping privileges
Sep 17 00:33:36.806342 osdx dnscrypt-proxy[674267]: Network connectivity detected
Sep 17 00:33:36.806377 osdx dnscrypt-proxy[674267]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:33:36.806382 osdx dnscrypt-proxy[674267]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:33:36.806400 osdx dnscrypt-proxy[674267]: Firefox workaround initialized
Sep 17 00:33:36.806406 osdx dnscrypt-proxy[674267]: Loading the set of cloaking rules from [/tmp/tmp0js89f1g]
Sep 17 00:33:36.947874 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:33:36.948391 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:33:36.956348 osdx dnscrypt-proxy[674267]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 49199
Sep 17 00:33:36.956361 osdx dnscrypt-proxy[674267]: [RD] OK (DoH) - rtt: 132ms
Sep 17 00:33:36.956369 osdx dnscrypt-proxy[674267]: Server with the lowest initial latency: RD (rtt: 132ms)
Sep 17 00:33:36.956372 osdx dnscrypt-proxy[674267]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:33:36.976868 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:33:37.135122 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'show host lookup teldat.com type A'.

Example 5

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_RSA_WITH_3DES_EDE_CBC_SHA
set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

Cipher suite: 49200
Show output
Sep 17 00:33:37.401661 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:33:37.402940 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:33:37.403001 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:33:37.418710 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:33:37.756538 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:33:37.812408 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'delete '.
Sep 17 00:33:37.956595 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system login user admin authentication plaintext-password ******'.
Sep 17 00:33:38.044303 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:33:38.187914 osdx ubnt-cfgd[674365]: inactive
Sep 17 00:33:38.218186 osdx systemd[1]: Stopping dnscrypt-proxy.service - DNSCrypt client proxy...
Sep 17 00:33:38.218235 osdx dnscrypt-proxy[674267]: Stopped.
Sep 17 00:33:38.219903 osdx systemd[1]: dnscrypt-proxy.service: Deactivated successfully.
Sep 17 00:33:38.220045 osdx systemd[1]: Stopped dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:33:38.289432 osdx WARNING[674431]: No supported link modes on interface eth0
Sep 17 00:33:38.290981 osdx modulelauncher[674431]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:33:38.290998 osdx modulelauncher[674431]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:33:38.292285 osdx modulelauncher[674431]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:33:38.292297 osdx modulelauncher[674431]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:33:38.319891 osdx ca-certificates[674453]: Clearing symlinks in /etc/ssl/certs...
Sep 17 00:33:38.691277 osdx ca-certificates[675030]: done.
Sep 17 00:33:38.695858 osdx ca-certificates[675039]: Updating certificates in /etc/ssl/certs...
Sep 17 00:33:39.333011 osdx ubnt-cfgd[675897]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:33:39.344715 osdx ca-certificates[675903]: 142 added, 0 removed; done.
Sep 17 00:33:39.349150 osdx ca-certificates[675909]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:33:39.353131 osdx ca-certificates[675911]: done.
Sep 17 00:33:39.418864 osdx INFO[675923]: FRR daemons did not change
Sep 17 00:33:39.546782 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:33:39.547483 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:33:39.586569 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:33:40.998085 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:33:41.602372 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:33:41.658537 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:33:41.762024 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:33:41.832922 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:33:41.940536 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:33:42.000587 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_RSA_WITH_3DES_EDE_CBC_SHA'.
Sep 17 00:33:42.096120 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384'.
Sep 17 00:33:42.145626 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:33:42.265423 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:33:42.330570 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:33:42.445478 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:33:42.524718 osdx ubnt-cfgd[675980]: inactive
Sep 17 00:33:42.552618 osdx INFO[675993]: FRR daemons did not change
Sep 17 00:33:42.565239 osdx ca-certificates[676009]: Updating certificates in /etc/ssl/certs...
Sep 17 00:33:43.073296 osdx ubnt-cfgd[677021]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:33:43.082115 osdx ca-certificates[677027]: 1 added, 0 removed; done.
Sep 17 00:33:43.085617 osdx ca-certificates[677033]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:33:43.088196 osdx ca-certificates[677035]: done.
Sep 17 00:33:43.114495 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:33:43.160430 osdx WARNING[677104]: No supported link modes on interface eth0
Sep 17 00:33:43.162197 osdx modulelauncher[677104]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:33:43.162212 osdx modulelauncher[677104]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:33:43.163703 osdx modulelauncher[677104]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:33:43.163712 osdx modulelauncher[677104]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:33:43.282813 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:33:43.308933 osdx dnscrypt-proxy[677148]: dnscrypt-proxy 2.0.45
Sep 17 00:33:43.308998 osdx dnscrypt-proxy[677148]: Network connectivity detected
Sep 17 00:33:43.309200 osdx dnscrypt-proxy[677148]: Dropping privileges
Sep 17 00:33:43.311586 osdx dnscrypt-proxy[677148]: Network connectivity detected
Sep 17 00:33:43.311624 osdx dnscrypt-proxy[677148]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:33:43.311629 osdx dnscrypt-proxy[677148]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:33:43.311650 osdx dnscrypt-proxy[677148]: Firefox workaround initialized
Sep 17 00:33:43.311656 osdx dnscrypt-proxy[677148]: Loading the set of cloaking rules from [/tmp/tmp3iqgi6g2]
Sep 17 00:33:43.448997 osdx dnscrypt-proxy[677148]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 49200
Sep 17 00:33:43.449021 osdx dnscrypt-proxy[677148]: [RD] OK (DoH) - rtt: 119ms
Sep 17 00:33:43.449031 osdx dnscrypt-proxy[677148]: Server with the lowest initial latency: RD (rtt: 119ms)
Sep 17 00:33:43.449036 osdx dnscrypt-proxy[677148]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:33:43.456391 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:33:43.457046 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:33:43.473290 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:33:43.615762 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'show host lookup teldat.com type A'.

Example 6

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy cipher 1 algorithm TLS_RSA_WITH_3DES_EDE_CBC_SHA
set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
set service dns proxy log level 0
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

Cipher suite: 52392
Show output
Sep 17 00:33:43.871830 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:33:43.874498 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:33:43.874555 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:33:43.881260 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:33:44.192184 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:33:44.249573 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'delete '.
Sep 17 00:33:44.369304 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system login user admin authentication plaintext-password ******'.
Sep 17 00:33:44.427832 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:33:44.522042 osdx ubnt-cfgd[677246]: inactive
Sep 17 00:33:44.546492 osdx dnscrypt-proxy[677148]: Stopped.
Sep 17 00:33:44.546591 osdx systemd[1]: Stopping dnscrypt-proxy.service - DNSCrypt client proxy...
Sep 17 00:33:44.547793 osdx systemd[1]: dnscrypt-proxy.service: Deactivated successfully.
Sep 17 00:33:44.547907 osdx systemd[1]: Stopped dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:33:44.605423 osdx WARNING[677312]: No supported link modes on interface eth0
Sep 17 00:33:44.606991 osdx modulelauncher[677312]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:33:44.607008 osdx modulelauncher[677312]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:33:44.608173 osdx modulelauncher[677312]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:33:44.608183 osdx modulelauncher[677312]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:33:44.625411 osdx ca-certificates[677334]: Clearing symlinks in /etc/ssl/certs...
Sep 17 00:33:44.918988 osdx ca-certificates[677911]: done.
Sep 17 00:33:44.922590 osdx ca-certificates[677920]: Updating certificates in /etc/ssl/certs...
Sep 17 00:33:45.384285 osdx ubnt-cfgd[678778]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:33:45.392520 osdx ca-certificates[678784]: 142 added, 0 removed; done.
Sep 17 00:33:45.395397 osdx ca-certificates[678790]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:33:45.398164 osdx ca-certificates[678792]: done.
Sep 17 00:33:45.448206 osdx INFO[678804]: FRR daemons did not change
Sep 17 00:33:45.575946 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:33:45.576387 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:33:45.592241 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:33:47.093366 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:33:47.811633 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:33:47.926463 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Sep 17 00:33:48.077497 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Sep 17 00:33:48.186741 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Sep 17 00:33:48.315538 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash 9d38fcf8d31bd0c819098a15b7711210323b893c2912cc4defd8ae8cb3fb99fb'.
Sep 17 00:33:48.417979 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 1 algorithm TLS_RSA_WITH_3DES_EDE_CBC_SHA'.
Sep 17 00:33:48.542246 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy cipher 2 algorithm TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256'.
Sep 17 00:33:48.655391 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy log level 0'.
Sep 17 00:33:48.763792 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:33:48.843221 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:33:49.028553 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:33:49.132429 osdx ubnt-cfgd[678859]: inactive
Sep 17 00:33:49.165978 osdx INFO[678872]: FRR daemons did not change
Sep 17 00:33:49.180990 osdx ca-certificates[678888]: Updating certificates in /etc/ssl/certs...
Sep 17 00:33:49.750526 osdx ubnt-cfgd[679900]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:33:49.758610 osdx ca-certificates[679906]: 1 added, 0 removed; done.
Sep 17 00:33:49.761508 osdx ca-certificates[679912]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:33:49.764263 osdx ca-certificates[679914]: done.
Sep 17 00:33:49.794529 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:33:49.846957 osdx WARNING[679983]: No supported link modes on interface eth0
Sep 17 00:33:49.848520 osdx modulelauncher[679983]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:33:49.848535 osdx modulelauncher[679983]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:33:49.849958 osdx modulelauncher[679983]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:33:49.849969 osdx modulelauncher[679983]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:33:49.962946 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:33:49.991572 osdx dnscrypt-proxy[680027]: dnscrypt-proxy 2.0.45
Sep 17 00:33:49.991859 osdx dnscrypt-proxy[680027]: Network connectivity detected
Sep 17 00:33:49.992112 osdx dnscrypt-proxy[680027]: Dropping privileges
Sep 17 00:33:49.994647 osdx dnscrypt-proxy[680027]: Network connectivity detected
Sep 17 00:33:49.994683 osdx dnscrypt-proxy[680027]: Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:33:49.994687 osdx dnscrypt-proxy[680027]: Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:33:49.994708 osdx dnscrypt-proxy[680027]: Firefox workaround initialized
Sep 17 00:33:49.994713 osdx dnscrypt-proxy[680027]: Loading the set of cloaking rules from [/tmp/tmpoae3zfsb]
Sep 17 00:33:50.136991 osdx dnscrypt-proxy[680027]: [RD] TLS version: 303 - Protocol: h2 - Cipher suite: 52392
Sep 17 00:33:50.137010 osdx dnscrypt-proxy[680027]: [RD] OK (DoH) - rtt: 119ms
Sep 17 00:33:50.137019 osdx dnscrypt-proxy[680027]: Server with the lowest initial latency: RD (rtt: 119ms)
Sep 17 00:33:50.137024 osdx dnscrypt-proxy[680027]: dnscrypt-proxy is ready - live servers: 1
Sep 17 00:33:50.176618 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:33:50.177261 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:33:50.205606 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:33:50.368293 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'show host lookup teldat.com type A'.