SSL certificate validation failure during systemd-resolved DNS stub integration
24.5K reputation · 27 Apr 2023, 04:41 UTC
On Arch Linux, integrating systemd-resolved typically involves linking /etc/resolv.conf to /run/systemd/resolve/stub-resolv.conf to utilize the local DNS stub listener at 127.0.0.53.
When this configuration is active, certain applications may encounter SSL/TLS handshake failures if the DNS resolution process introduces latency or returns unexpected records that interfere with the certificate validation chain provided by the ca-certificates package.
There is uncertainty regarding how the local stub listener interacts with specific library-level certificate validation when DNSSEC is enabled or when the system clock is out of sync during the resolution phase.
- Does the
systemd-resolvedstub listener affect the timing of the TLS handshake in a way that triggers validity period errors? - How does the interaction between the stub resolver and the
ca-certificatestrust store change when using split-DNS configurations?