Alice utilise witches.town. Vous pouvez læ suivre et interagir si vous possédez un compte quelque part dans le "fediverse".

Oh come on it's impossible ?! Why that domain only ?! Why only on Free's DNS (212.27.40.241). Is anyone else facing this issue ? Anyone using Free facing issues resolving nixos.org or other domain names ?

@Sasha (don't have access to a proper computer, sorry

dig nixos.org

dig +cd nixos.org

And post the results. (+cd = checking disabled, to see if this is a DNSSEC problem)

@bortzmeyer I had done a simple `dig nixos.org` (I don't know what +cd does) but I got the same result with `+cd` :

; <<>> DiG 9.11.2 <<>> nixos.org
;; global options: +cmd
;; connection timed out; no servers could be reached

A result I interpret as the DNS process on their server crashing and thus maybe closing the socket unexpectedly ? Because I can garantee the server can be reached : I can resolve any other domain name without any trouble at all.

@Sasha @bortzmeyer looks like your local nameserver has trouble, what's in /etc/resolv.conf (or whatever equivalent of it you might have).

I have a crappy router that tends to fill up its DNS cache and stop resolving new names, it answers to the old (known) ones only.

Alice @Sasha

@saper @bortzmeyer Yeah it contains my provider's DNS servers (212.27.40.24{0,1}), which can apparently resolve any other domain name like a charm, and conversely I've been able to resolve nixos.org by asking directly other DNS (yeah, I did it with @8.8.8.8 ^^) and also on a VPS I rent. So yeah, I would suppose my provider's servers have gone nut, but I'm very surprised I should be the only one to notice something. Plus I thought that'd be the kind of bug they would fix within minutes.

@Sasha @saper Nope. Routing issues can last months. People typically do not monitor that.

@bortzmeyer @saper Wow thanks a lot for your answers (and sorry for failing to read what you had already written plainly 😅). So that means that nixos.org is not well configured but that Free isn't connected to that part of Internet ?! But I can ping that IP, I'm sure I can reach the site if I write an entry in /etc/hosts.

@Sasha @saper Nixos people should add at least one name server outside of Udag's AS.

Udag people should investigate routing and talk with Free.

Free people should investigate and talk to Udag (easier said than done)

@bortzmeyer @saper I guess I can drop a line to someone at NixOS, I should be able to write to free as one of their customer (even though I fear an answer around the lines of «send us your box back»…).

So what should I do in the meantime ? Simply leave that line in /etc/hosts ? Use someone else's resolver ? (I won't use Google's, they already know way too much about me 😁).

Anyway thanks again for the explanation, I'm gonna have to learn to play with those RIPE Atlas probes, they seem so useful !!

@Sasha @bortzmeyer /etc/hosts is fine. Do tell Free, since it is most likely their routing problem.

@Sasha @saper Having your own resolver is good anyway bortzmeyer.org/son-propre-reso and, if it has IPv6, it works with Udag even if hosted by Free (nixos.org works for me).

@saper @Sasha But you have me :-) to perform traceroutes (or dozens of RIPE Atlas probes) : routing loop inside Free gist.github.com/bortzmeyer/5e2

@saper @Sasha Use RIPE Atlas probes, they are here for everyone :-)

@saper @bortzmeyer Yeah, not quite sure how you can do this either. How can you check what happens from within Free's network ? Surely it's not your provider ?

@Sasha @bortzmeyer if you host a RIPE atlas probe, you are allowed to play with all of them a bit.

@saper @Sasha Hosting is not strictly necessary. You can get credits by other means (being a LIR, or simply asking a friend, I have a lot of credits. Also, the RIPE-NCC gives easily to researchers or students.)

@bortzmeyer @Sasha I cannot reach 194.149.163.89 nor 194.149.163.90 from here