Source

Test suite to validate using one or multiple ciphers to protect DoH connection

Valid Source

Description

Configures a valid source with the expected minisign key and checks that everything works.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy server-name rd-server
set service dns proxy source RD minisign-key RWQevWtyQ8TtxKNFRpn66WSUliOyyKMMiuQzoWRxOxTiwOchGzCmwqjr
set service dns proxy source RD url 'http://10.215.168.1/~robot/RD-resolver.md'
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

(?m)^.*\[rd-server\] OK \(DoH\) - rtt: \d+ms$
Show output
Sep 17 00:27:05.306604 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:27:05.307733 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:27:05.307780 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:27:05.317851 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:27:05.612197 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 17 00:27:05.913689 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:27:06.028995 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:27:06.085984 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:27:06.207935 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:27:06.269196 osdx ubnt-cfgd[598210]: inactive
Sep 17 00:27:06.294893 osdx INFO[598221]: FRR daemons did not change
Sep 17 00:27:06.323743 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:27:06.383500 osdx WARNING[598292]: No supported link modes on interface eth0
Sep 17 00:27:06.391916 osdx modulelauncher[598292]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:27:06.391939 osdx modulelauncher[598292]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:27:06.393758 osdx modulelauncher[598292]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:27:06.393769 osdx modulelauncher[598292]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:27:06.613892 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:27:06.614478 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:27:06.634949 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:27:06.831363 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Sep 17 00:27:06.901693 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 17 00:27:07.053741 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:27:07.120943 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:27:07.228181 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy source RD url http://10.215.168.1/~robot/RD-resolver.md'.
Sep 17 00:27:07.297275 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy source RD minisign-key RWQevWtyQ8TtxKNFRpn66WSUliOyyKMMiuQzoWRxOxTiwOchGzCmwqjr'.
Sep 17 00:27:07.431497 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name rd-server'.
Sep 17 00:27:07.578456 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:27:07.678661 osdx ubnt-cfgd[598397]: inactive
Sep 17 00:27:07.716760 osdx INFO[598406]: FRR daemons did not change
Sep 17 00:27:07.748559 osdx ca-certificates[598422]: Updating certificates in /etc/ssl/certs...
Sep 17 00:27:08.419312 osdx ubnt-cfgd[599434]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:27:08.429843 osdx ca-certificates[599438]: 1 added, 0 removed; done.
Sep 17 00:27:08.432678 osdx ca-certificates[599446]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:27:08.435343 osdx ca-certificates[599448]: done.
Sep 17 00:27:08.492140 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:27:08.502396 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:27:08.503036 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:27:08.522623 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] dnscrypt-proxy 2.0.45
Sep 17 00:27:08.522867 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] Network connectivity detected
Sep 17 00:27:08.522955 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] Dropping privileges
Sep 17 00:27:08.525632 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] Network connectivity detected
Sep 17 00:27:08.525683 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:27:08.525683 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:27:08.537398 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [WARNING] /var/cache/dnscrypt-proxy/RD.md: open /var/cache/dnscrypt-proxy/sf-3erkulmjtnngmloh.tmp: permission denied
Sep 17 00:27:08.537398 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] Source [RD] loaded
Sep 17 00:27:08.537526 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [WARNING] Missing stamp for server [server-name`]
Sep 17 00:27:08.537526 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [WARNING] Error in source [RD]: [Missing stamp for server [server-name`]] -- Continuing with reduced server count [1]
Sep 17 00:27:08.537526 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] Firefox workaround initialized
Sep 17 00:27:08.537526 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpy_ngnyin]
Sep 17 00:27:08.537566 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:27:08.699753 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 17 00:27:08.860400 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] [rd-server] OK (DoH) - rtt: 140ms
Sep 17 00:27:08.860400 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] Server with the lowest initial latency: rd-server (rtt: 140ms)
Sep 17 00:27:08.860400 osdx dnscrypt-proxy[599452]: [2026-09-17 00:27:08] [NOTICE] dnscrypt-proxy is ready - live servers: 1

Valid Source With Prefix

Description

Configures a valid source with the expected minisign key and checks that everything works. Additionally, uses a prefix to avoid the duplicity of servers with the same name.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy server-name PRIVATE-rd-server
set service dns proxy source RD minisign-key RWQevWtyQ8TtxKNFRpn66WSUliOyyKMMiuQzoWRxOxTiwOchGzCmwqjr
set service dns proxy source RD prefix PRIVATE-
set service dns proxy source RD url 'http://10.215.168.1/~robot/RD-resolver.md'
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

(?m)^.*\[PRIVATE-rd-server\] OK \(DoH\) - rtt: \d+ms$
Show output
Sep 17 00:27:16.308550 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 17 00:27:16.311039 osdx systemd-journald[303514]: Received client request to rotate journal, rotating.
Sep 17 00:27:16.311106 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 17 00:27:16.318845 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal clear'.
Sep 17 00:27:16.528869 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 17 00:27:16.758774 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:27:16.852359 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 17 00:27:16.921419 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Sep 17 00:27:17.027818 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:27:17.094549 osdx ubnt-cfgd[601192]: inactive
Sep 17 00:27:17.126640 osdx INFO[601203]: FRR daemons did not change
Sep 17 00:27:17.163029 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 17 00:27:17.217570 osdx WARNING[601274]: No supported link modes on interface eth0
Sep 17 00:27:17.219058 osdx modulelauncher[601274]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 17 00:27:17.219075 osdx modulelauncher[601274]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 17 00:27:17.220275 osdx modulelauncher[601274]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 17 00:27:17.220284 osdx modulelauncher[601274]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 17 00:27:17.432864 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:27:17.433417 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:27:17.479808 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:27:17.627016 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Sep 17 00:27:17.698455 osdx OSDxCLI[538347]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 17 00:27:17.874431 osdx OSDxCLI[538347]: User 'admin' entered the configuration menu.
Sep 17 00:27:17.942103 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Sep 17 00:27:18.047867 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy source RD url http://10.215.168.1/~robot/RD-resolver.md'.
Sep 17 00:27:18.114725 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy source RD minisign-key RWQevWtyQ8TtxKNFRpn66WSUliOyyKMMiuQzoWRxOxTiwOchGzCmwqjr'.
Sep 17 00:27:18.208110 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy source RD prefix PRIVATE-'.
Sep 17 00:27:18.269079 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'set service dns proxy server-name PRIVATE-rd-server'.
Sep 17 00:27:18.368821 osdx OSDxCLI[538347]: User 'admin' added a new cfg line: 'show working'.
Sep 17 00:27:18.448578 osdx ubnt-cfgd[601380]: inactive
Sep 17 00:27:18.473802 osdx INFO[601389]: FRR daemons did not change
Sep 17 00:27:18.487477 osdx ca-certificates[601405]: Updating certificates in /etc/ssl/certs...
Sep 17 00:27:19.023616 osdx ubnt-cfgd[602417]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Sep 17 00:27:19.034516 osdx ca-certificates[602422]: 1 added, 0 removed; done.
Sep 17 00:27:19.038490 osdx ca-certificates[602429]: Running hooks in /etc/ca-certificates/update.d...
Sep 17 00:27:19.041891 osdx ca-certificates[602431]: done.
Sep 17 00:27:19.107458 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Sep 17 00:27:19.116640 osdx cfgd[1899]: [538347]Completed change to active configuration
Sep 17 00:27:19.117222 osdx OSDxCLI[538347]: User 'admin' committed the configuration.
Sep 17 00:27:19.135728 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] dnscrypt-proxy 2.0.45
Sep 17 00:27:19.135969 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] Network connectivity detected
Sep 17 00:27:19.136065 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] Dropping privileges
Sep 17 00:27:19.138819 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] Network connectivity detected
Sep 17 00:27:19.138919 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] Now listening to 127.0.0.1:53 [UDP]
Sep 17 00:27:19.138919 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] Now listening to 127.0.0.1:53 [TCP]
Sep 17 00:27:19.140067 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [WARNING] /var/cache/dnscrypt-proxy/RD.md: open /var/cache/dnscrypt-proxy/sf-k2eejliz24k3ovlb.tmp: permission denied
Sep 17 00:27:19.140067 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] Source [RD] loaded
Sep 17 00:27:19.140146 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [WARNING] Missing stamp for server [PRIVATE-server-name`]
Sep 17 00:27:19.140146 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [WARNING] Error in source [RD]: [Missing stamp for server [PRIVATE-server-name`]] -- Continuing with reduced server count [1]
Sep 17 00:27:19.140146 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] Firefox workaround initialized
Sep 17 00:27:19.140146 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpes8uekvy]
Sep 17 00:27:19.146257 osdx OSDxCLI[538347]: User 'admin' left the configuration menu.
Sep 17 00:27:19.264470 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] [PRIVATE-rd-server] OK (DoH) - rtt: 108ms
Sep 17 00:27:19.264470 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] Server with the lowest initial latency: PRIVATE-rd-server (rtt: 108ms)
Sep 17 00:27:19.264470 osdx dnscrypt-proxy[602435]: [2026-09-17 00:27:19] [NOTICE] dnscrypt-proxy is ready - live servers: 1

Invalid Source

Description

Configures an invalid source with a random minisign key and expects it to fail.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy log level 0
set service dns proxy server-name rd-server
set service dns proxy source RD minisign-key oV7harGMjBlqxLmmJ34to28p
set service dns proxy source RD url 'http://10.215.168.1/~robot/invalid-source'
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Invalid Minisign Key

Description

Configures a valid source but with an incorrect minisign key, which should fail.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy log level 0
set service dns proxy server-name rd-server
set service dns proxy source RD minisign-key InvalidMinisignKey==
set service dns proxy source RD url 'http://10.215.168.1/~robot/RD-resolver.md'
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'