On Thu, 25 Aug 2011, Thomas Moschny wrote: > 2011/8/25 Paul Wouters <paul@xxxxxxxxxxxxx>: >> Again, this is based on f14, not f15/f16. I am not sure how much this has been >> addressed. But if we want DNSSEC validation on the endnode, at the very least >> 127.0.0.1:53 needs to be left free. > > Are you sure the dnsmasq instance started by libvirt is really > grabbing 127.0.0.1:53? > > In my experiments it did not, and the issue instead was that the other > DNS server [1] wanted to grab port 53 on *all* interfaces. > > - Thomas > > [1] In my case that was a second instance of dnsmasq, and I had to set > --interface=lo and --bind-interfaces. I'll double check with f16 alpha on some iron and if it is still a problem, get back and file a bug to formalise talking about this. Paul -- devel mailing list devel@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/devel