X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Fdebian-org%2Fmisc%2Fhoster.yaml;h=575b5e94a0e12fdff455dad01dafb753a4d9d1c9;hb=3a4fde5448956443511a1ce18ab4162a334eb30a;hp=2be53d47f8f5b1098886e30f90da19ace0a865c1;hpb=34818ff69633cc6a45f5a1da8ff4e3a61cbb97de;p=mirror%2Fdsa-puppet.git diff --git a/modules/debian-org/misc/hoster.yaml b/modules/debian-org/misc/hoster.yaml index 2be53d47f..575b5e94a 100644 --- a/modules/debian-org/misc/hoster.yaml +++ b/modules/debian-org/misc/hoster.yaml @@ -3,13 +3,16 @@ netrange: - 87.106.0.0/16 - 2001:8d8:81:1520::/64 + nameservers_break_dnssec: true nameservers: [87.106.64.251, 195.20.224.99, 195.20.224.234] + # for i in `awk '$1=="nameserver" {print $2}' /etc/resolv.conf; [ -e /etc/unbound/unbound.conf ] && awk '$1=="forward-addr:" {print $2}' /etc/unbound/unbound.conf`; do dig +dnssec @$i -t ns . | grep RRSIG || echo BROKEN; echo;echo $i; echo;read; done 1und1-sec: netrange: - 195.20.242.64/26 - 212.227.126.32/27 - 2001:8d8:2:1::/64 searchpaths: [debprivate-oneandone.debian.org] + nameservers_break_dnssec: true nameservers: [195.20.224.99, 195.20.224.234, 87.106.64.251] accumu: netrange: @@ -22,21 +25,24 @@ ana: netrange: - 150.203.164.0/24 - 2001:388:1034:2900::64 + nameservers_break_dnssec: true nameservers: [150.203.1.10, 150.203.164.10, 150.203.164.9] arm: netrange: - 217.140.96.58/29 + nameservers_break_dnssec: true nameservers: [158.43.128.1, 217.140.108.113] br: # University Federal do Parana (.br) netrange: - 200.17.192.0/19 - nameservers: [200.17.202.1, 200.17.202.3] + nameservers: [200.236.31.1, 200.17.202.3] brainfood: netrange: - 70.103.162.0/24 searchpaths: [debprivate-brainfood.debian.org] - nameservers: [70.103.162.29, 70.103.162.4] + # all hosts have their own recursor + nameservers: [] brown: netrange: - 128.148.0.0/16 @@ -45,6 +51,7 @@ brown: carnet: netrange: - 193.198.0.0/16 + nameservers_break_dnssec: true nameservers: [161.53.160.3, 161.53.123.3] csail: # mit @@ -62,7 +69,7 @@ darmstadt: - 82.195.75.32/28 - 2001:41b8:202:deb::/64 searchpaths: [debprivate-darmstadt.debian.org] - nameservers: [82.195.75.81, 82.195.66.249, 217.198.242.225] + nameservers: [82.195.66.249, 217.198.242.225] dgi: netrange: - 93.94.130.128/26 @@ -70,11 +77,12 @@ dgi: freenet: netrange: - 62.104.0.0/16 + nameservers_break_dnssec: true nameservers: [194.97.3.83, 62.104.64.3, 194.97.3.11] ftcollins: netrange: - 192.25.206.0/24 - searchpaths: [debprivate-debprivate-ftcollins.debian.org] + searchpaths: [debprivate-ftcollins.debian.org] nameservers: [192.25.206.33, 192.25.206.57] # only applicable for hosts that are recursive anyway: allow_dns_query: [192.25.206.0/24] @@ -87,7 +95,8 @@ grnet: helsinki: netrange: - 193.167.160.0/23 - nameservers: [128.214.9.15, 218.214.4.29] + # all hosts have their own recursor + nameservers: [] isc: netrange: - 149.20.0.0/16 @@ -101,13 +110,17 @@ osuosl: netrange: - 140.211.166.0/25 - 140.211.15.0/24 + nameservers_break_dnssec: true nameservers: [140.211.166.130, 140.211.166.131, 216.165.191.54] sanger: netrange: - 193.62.202.24/29 - nameservers: [193.62.203.96, 193.62.203.97] + # broken with dnssec + # nameservers: [193.62.203.96, 193.62.203.97] + #resolvoptions: [single-request] + nameservers: [193.62.202.28, 193.62.202.29] searchpaths: [debprivate-sanger.debian.org] - resolvoptions: [single-request] + allow_dns_query: [193.62.202.24/29] rapidswitch: netrange: - 193.201.200.0/23 @@ -116,12 +129,16 @@ sil: netrange: - 86.59.118.144/28 searchpaths: [debprivate-sil.debian.org] - nameservers: [213.129.232.1, 213.129.226.2] + #nameservers_break_dnssec: true + #nameservers: [213.129.232.1, 213.129.226.2] + nameservers: [86.59.118.147, 86.59.118.148] + allow_dns_query: [86.59.118.144/28 2001:858:2:2::/64] scanplus: netrange: - 212.211.132.0/26 - 212.211.132.248/29 - 2001:a78::/64 + nameservers_break_dnssec: true nameservers: [212.211.132.4, 212.75.32.4] snowman: netrange: @@ -130,13 +147,15 @@ snowman: telegrafxs4all: netrange: - 82.94.249.152/29 + nameservers_break_dnssec: true nameservers: [194.109.6.66] ubcece: netrange: - 137.82.84.64/27 - 206.12.19.0/24 searchpaths: [debprivate-ubc.debian.org] - nameservers: [206.12.19.5, 137.82.1.1, 142.103.1.1] + nameservers: [206.12.19.214, 2607:f8f0:610:4000:224:81ff:fea7:e952, 206.12.19.20, 2607:f8f0:610:4000:218:feff:fe76:2ed0, 206.12.19.21, 2607:f8f0:610:4000:21c:c4ff:fee5:e890] + allow_dns_query: [137.82.84.64/27, 206.12.19.0/24, 2607:f8f0:610:4000::/64] ugent: netrange: - 157.193.0.0/16 @@ -144,12 +163,15 @@ ugent: umn: netrange: - 128.101.240.212 + nameservers_break_dnssec: true nameservers: [128.101.101.101, 134.84.84.84] utwente: netrange: - 130.89.0.0/16 - 2001:0610:1908::/48 - nameservers: [130.89.2.2, 130.89.2.3] + # broken with dnssec + #nameservers: [130.89.2.2, 130.89.2.3] + nameservers: [] xs4all: netrange: - 194.109.137.216/29 @@ -161,6 +183,7 @@ ynic: zivit: netrange: - 80.245.144.0/22 + nameservers_break_dnssec: true nameservers: [80.245.147.53, 80.245.147.54] # vim:set et: