-
Notifications
You must be signed in to change notification settings - Fork 1.1k
systemd
dnscrypt-proxy can be started with systemd. The -service install option will install a systemd service for you.
Only read what follows if you are a systemd expert and think you need a complicated configuration. Everybody else should just follow the generic Linux installation instructions, not this guide. (However, systemd socket activation can be easily disabled).
Socket emulation from systemd ("socket activation") may work but this is not a well-tested configuration. Use native sockets (listen_addresses in the dnscrypt-proxy.toml configuration file) whenever possible.
Do not open a support ticket if you are using dnscrypt-proxy with systemd sockets.
Packages from distribution repositories (e.g. Arch Linux, Ubuntu) may set up systemd sockets by default.
In order to use systemd sockets, and only these, the listen_addresses option in the dnscrypt-proxy.toml configuration file should be empty:
listen_addresses = []While using socket activation, the following warnings are expected and can be safely ignored:
systemd[1]: dnscrypt-proxy.socket: TCP_NODELAY failed: Protocol not available
systemd[1]: dnscrypt-proxy.socket: TCP_DEFER_ACCEPT failed: Protocol not available
They occur because systemd tries to apply TCP-only options to a UDP socket. This should not affect functionality.
If the DynamicUser=yes option is enabled in the systemd service, you may need to adjust the log and cache file paths in dnscrypt-proxy.toml. Put them under /var/log/dnscrypt-proxy/ and /var/cache/dnscrypt-proxy/, respectively (create those directories if needed).
Here are sample systemd units for a standalone installation:
/lib/systemd/system/dnscrypt-proxy.service:
[Unit]
Description=DNSCrypt-proxy client
Documentation=https://github.com/DNSCrypt/dnscrypt-proxy/wiki
Requires=dnscrypt-proxy.socket
After=network.target
Before=nss-lookup.target
Wants=nss-lookup.target
[Service]
NonBlocking=true
ExecStart=/usr/bin/dnscrypt-proxy --config /etc/dnscrypt-proxy/dnscrypt-proxy.toml
ProtectHome=yes
ProtectControlGroups=yes
ProtectKernelModules=yes
# Run dnscrypt-proxy as an unprivileged user with
# a temporarily assigned UID/GID. See man:systemd.exec
# for more information. Requires systemd 232+.
DynamicUser=yes
CacheDirectory=dnscrypt-proxy
LogsDirectory=dnscrypt-proxy
RuntimeDirectory=dnscrypt-proxy
[Install]
Also=dnscrypt-proxy.socket
WantedBy=multi-user.target
/lib/systemd/system/dnscrypt-proxy.socket:
[Unit]
Description=DNSCrypt-proxy socket
Documentation=https://github.com/DNSCrypt/dnscrypt-proxy/wiki
Before=nss-lookup.target
Wants=nss-lookup.target
Wants=dnscrypt-proxy-resolvconf.service
[Socket]
ListenStream=127.0.2.1:53
ListenDatagram=127.0.2.1:53
NoDelay=true
DeferAcceptSec=1
[Install]
WantedBy=sockets.target
/lib/systemd/system/dnscrypt-proxy-resolvconf.service:
[Unit]
Description=DNSCrypt proxy resolvconf support
Documentation=man:dnscrypt-proxy(8)
After=dnscrypt-proxy.socket
Requires=dnscrypt-proxy.socket
ConditionFileIsExecutable=/sbin/resolvconf
[Service]
Type=oneshot
RemainAfterExit=true
ExecStart=/bin/sh -c 'systemctl show dnscrypt-proxy.socket \
| grep "Listen.*Datagram" \
| cut -d "=" -f 2 \
| cut -d ":" -f 1 \
| awk \'{ print "nameserver " $1 }\' \
| /sbin/resolvconf -a lo.dnscrypt-proxy'
ExecStop=/sbin/resolvconf -d lo.dnscrypt-proxy
[Install]
WantedBy=multi-user.target
Also=dnscrypt-proxy.socket
If you would like to use multiple interfaces, you can use multiple socket files to connect to the same service.
/lib/systemd/system/dnscrypt-proxy-lo.socket:
[Unit]
Description=DNSCrypt-proxy loopback socket
Documentation=https://github.com/DNSCrypt/dnscrypt-proxy/wiki
Before=nss-lookup.target
Wants=nss-lookup.target
Wants=dnscrypt-proxy-resolvconf.service
[Socket]
BindToDevice=lo
Service=dnscrypt-proxy.service
ListenStream=127.0.2.1:53
ListenDatagram=127.0.2.1:53
NoDelay=true
DeferAcceptSec=1
[Install]
WantedBy=sockets.target
/lib/systemd/system/dnscrypt-proxy-eth.socket:
[Unit]
Description=DNSCrypt-proxy ethernet socket
Documentation=https://github.com/DNSCrypt/dnscrypt-proxy/wiki
Before=nss-lookup.target
Wants=nss-lookup.target
Wants=dnscrypt-proxy-resolvconf.service
[Socket]
# Use the values from ifconfig to uncomment and fill in the appropriate values for
# the 'BindToDevice', 'ListenStream', and 'ListenDatagram' fields.
#BindToDevice=eth0
Service=dnscrypt-proxy.service
#ListenStream=192.168.0.0:53
#ListenDatagram=192.168.0.0:53
#ListenStream=[fe80::]:53
#ListenDatagram=[fe80::]:53
BindIPv6Only=both
NoDelay=true
DeferAcceptSec=1
[Install]
WantedBy=sockets.target
Enable the services with systemctl enable dnscrypt-proxy dnscrypt-proxy-resolvconf. The following commands also appear to be sufficient:
sudo systemctl start dnscrypt-proxy.socket
sudo systemctl enable dnscrypt-proxy.socket
sudo systemctl start dnscrypt-proxy.service
sudo systemctl enable dnscrypt-proxy.service
--
Before using DNSCrypt-Proxy without systemd socket activation, consider the advantages and disadvantages. For example, lead developer Frank Denis recommends not using systemd sockets at all. On the other hand, some users consider systemd socket activation a better choice (for more information, see [1], which contains various threads about systemd and socket activation).
Disabling systemd socket activation is relatively simple, if not trivial. The following short description includes comments and commands to achieve this goal. (Please note that mousepad is a simple text editor. Use your preferred application or editor.)
# Stop and disable socket units (it seems,
# that using the `mask` command is not needed).
# -------------------------------------------
sudo systemctl stop dnscrypt-proxy.socket
sudo systemctl disable dnscrypt-proxy.socket
# Edit and comment out all systemd socket-related options
# (e.g. `#Also=dnscrypt-proxy.socket`) found in both files.
# ---------------------------------------------------------
sudo mousepad /lib/systemd/system/dnscrypt-proxy.service
sudo mousepad /lib/systemd/system/dnscrypt-proxy-resolvconf.service
# Reload the systemd configuration manager to make
# the new changes available (NOTE: this command should
# be used every time the user modifies the `.service` files).
# -----------------------------------------------------
sudo systemctl daemon-reload
# Edit the DNSCrypt-Proxy configuration file, then add
# the IP address and port number (in 'IP:port' format)
# to the `listen_addresses` option, e.g. '127.0.0.1:53'.
# ----------------------------------------------------
sudo mousepad /etc/dnscrypt-proxy/dnscrypt-proxy.toml
# Restart DNSCrypt-Proxy service.
# -------------------------------
sudo systemctl restart dnscrypt-proxy.service
# Check that everything is working (there should be no
# 'WARNING' or 'FATAL' messages, and the information about
# "wiring systemd TCP/UDP sockets" should be replaced
# with "Now listening on TCP/UDP").
# ---------------------------------------------------
journalctl -u dnscrypt-proxy.service
systemctl status dnscrypt-proxy.serviceNOTE: "dnscrypt-proxy-resolvconf.service explicitly makes use of dnscrypt-proxy.socket" (see the ExecStart= option), but this file does not appear to be needed when systemd socket activation is disabled. There is no apparent difference whether dnscrypt-proxy-resolvconf.service is enabled or not. For a short discussion, see [2].
[1]. https://github.com/DNSCrypt/dnscrypt-proxy/issues?q=systemd+socket [2]. https://github.com/DNSCrypt/dnscrypt-proxy/issues/1394
--
To set up v2.0.45 with systemd (tested on Linux Mint 18.3 and Linux Mint 19.3), remove the dnscrypt-proxy-resolvconf line from dnscrypt-proxy.socket in the preceding instructions. In dnscrypt-proxy.toml, change the two lines to listen_addresses = ['127.0.0.1:53'] and ipv6_servers = false, and set appropriate cache and log directories (i.e., /var/cache/dnscrypt-proxy and /var/log/dnscrypt-proxy). Disable and delete dnscrypt-proxy-resolvconf.service with systemctl, delete /lib/systemd/system/dnscrypt-proxy-resolvconf.service, and reboot.
--
Are you familiar with systemd? Please update this Wiki page with relevant information!
- Home
- Installation
- Configuration
- Checking that your DNS traffic is encrypted
- Automatic Updates
- Server sources
- Combining blocklists
- Public Blocklist and other configuration files
- Building from source
- Run your own DNSCrypt server in under 10 minutes
- DNS stamps specifications
- Windows tips
- dnscrypt-proxy in the media
- Planned Features