Export thread

  • DNS Benchmark v2 Release 5 with Consultant License
    Guest:
    If you own any earlier release of our DNS Benchmark you may immediately download its release #5 replacement. Running an earlier release will detect the new release and help you upgrade.

    Although this release is cosmetic, appearance matters and affects ease of use. The biggest change, as seen in the image above, is that the DNS Benchmark now has a traditional Windows application menu to more fully expose its many features. This release is also "Consultant License Aware" and GRC will now issue a Consultant version when owners have previously purchased four "Personal Use" licenses. If you have previously purchased four DNSB licenses, or if you wish to upgrade your "Personal Use" license to Consultant, GRC's purchase process will direct you through that process.
    /Steve.
  • Be sure to checkout “Tips & Tricks”
    Dear Guest Visitor → Once you register and log-in please checkout the “Tips & Tricks” page for some very handy tips!

    /Steve.
  • BootAble – FreeDOS boot testing freeware

    To obtain direct, low-level access to a system's mass storage drives, SpinRite runs under a GRC-customized version of FreeDOS which has been modified to add compatibility with all file systems. In order to run SpinRite it must first be possible to boot FreeDOS.

    GRC's “BootAble” freeware allows anyone to easily create BIOS-bootable media in order to workout and confirm the details of getting a machine to boot FreeDOS through a BIOS. Once the means of doing that has been determined, the media created by SpinRite can be booted and run in the same way.

    The participants here, who have taken the time to share their knowledge and experience, their successes and some frustrations with booting their computers into FreeDOS, have created a valuable knowledgebase which will benefit everyone who follows.

    You may click on the image to the right to obtain your own copy of BootAble. Then use the knowledge and experience documented here to boot your computer(s) into FreeDOS. And please do not hesitate to ask questions – nowhere else can better answers be found.

    (You may permanently close this reminder with the 'X' in the upper right.)

DOT Greyed out

#1

GreenWine

GreenWine

Hi there - I did do a quick search for this issue and didn't see it, so hope I am not posting an issue already mentioned.

My DoT button is greyed out and I clicked it many times, it doesn't want to light up.

I am running on Ubuntu via Wine.

Attachments


  • Screenshot From 2025-12-11 14-24-17.png
    Screenshot From 2025-12-11 14-24-17.png
    33 KB · Views: 384

#2

Steve

Steve

DNSB looks at the resolvers in the list and enables those buttons when it finds working resolvers for each of those protocols. If your current resolver list does not have any DoT resolvers, or if your Linux/WINE doesn't support the required TCP/TLS protocol, then DNSB won't enable that button because it will not be able to benchmark any of the DoT resolvers that are in your resolver list.


#3

GreenWine

GreenWine

It may be the latter Mr G, I need to investigate. I manually tried to add my NextDNS DoT address into the list and it was accepted, but was instantly RED and the run bunchmark button becomes greyed out.

I have two in the list in this example, 1.1.1.1 and my nextdns (cropped for privacy) and I can't press run.

It seems odd that the latest Ubuntu wouldn't support all the new TCP/TLS stuff, but I do not know one way or the other. I will try and find out and report back.

Attachments


  • Screenshot From 2025-12-11 18-38-57.png
    Screenshot From 2025-12-11 18-38-57.png
    30.4 KB · Views: 409

#4

D

DanR

I have two in the list in this example, 1.1.1.1 and my nextdns (cropped for privacy) and I can't press run.
Try clicking the Ruby G.


#5

Steve

Steve

It seems odd that the latest Ubuntu wouldn't support all the new TCP/TLS stuff, but I do not know one way or the other. I will try and find out and report back.
I suspect that it's not the latest Ubuntu that doesn't support all the new TCP/TLS stuff. I agree with you that it certainly does. It's likely the WINE emulation of the Windows API that has not yet caught up.

I'm been thinking that a very useful way for me to spend my eventual retirement — once I inevitably wind down my commercial software company — would be working on WINE. I know the Windows API as well as anyone, and I've been VERY impressed by the popularity of WINE. Working to make WINE better would seem like a good use of my time, as well as fun, interesting and challenging. :)


#6

A

AlanD

I suspect that it's not the latest Ubuntu that doesn't support all the new TCP/TLS stuff. I agree with you that it certainly does. It's likely the WINE emulation of the Windows API that has not yet caught up.
AFAIK the version of WINE that is supplied from the Ubuntu repositories is 8.0.1 unless you manually install 9 or 10.


#7

GreenWine

GreenWine

Try clicking the Ruby G.
That sounds like cheating, but I shall.


#8

GreenWine

GreenWine

I hope my posts aren't coming across as tech support questions. I realise that it's a tool for Windows, but it does sound like attention was put into running it on other OS and Mr G did even mention that on SN.

I just wanted to share what appeared to be minor bugs. I would have loved to have been on the testing team. I'm not a coder, just an acomplished tinkerer, also, I'm just one of those guys that seems to encounter weird edge cases in life with whatever I encounter.


#9

GreenWine

GreenWine

AFAIK the version of WINE that is supplied from the Ubuntu repositories is 8.0.1 unless you manually install 9 or 10.
Yeah it is something like that. I love updating to the newest version of everything, except Windows 11 of course!


#10

peterblaise

peterblaise

@GreenWine" "... I'm not a coder, just an accomplished tinkerer, also, I'm just one of those guys that seems to encounter weird edge cases in life with whatever I encounter ..."

Mee too.

Welcome!


#11

B

brackerp

download file 2 times same result file corrupter

Attachments


  • Screenshot 2025-12-11 182351.png
    Screenshot 2025-12-11 182351.png
    11 KB · Views: 392

#12

peterblaise

peterblaise

@brackerp "... download file 2 times same result file corrupted - File or directory is corrupted and unreadable ..."

Command prompt, ChkDsk C: /f, reboot, try again.


#13

Steve

Steve

I hope my posts aren't coming across as tech support questions. I realise that it's a tool for Windows, but it does sound like attention was put into running it on other OS and Mr G did even mention that on SN.
100%! There is a substantial and significant population of people with Linux and Mac machines who are wishing to run this DNS Benchmark. So This has been very interesting — and important!

We HAVE now verified that modern code signing recognition requires WINE 9.0 at a minimum. I'm in the process of adding a detection of Wine version so that an explanatory dialog will be presented rather than that hostile error dialog.

If you wish to keep WINE 8 you can verify the forthcoming test tomorrow.


#14

Steve

Steve

I would have loved to have been on the testing team. I'm not a coder, just an acomplished tinkerer, also, I'm just one of those guys that seems to encounter weird edge cases in life with whatever I encounter.
Once this all settles and I finish my move into new new digs I'll be starting in on the next project. (I'll be delaying the immediate start on the next project until my wife and I have moved.) You are certainly welcome to participate in the development testing of ValiDrive 2, which will be the next project.

You'll need to find an old school NNTP client for your machine. See this page for details: https://www.grc.com/discussions.htm
Your contributions will certainly be welcome.


#15

GreenWine

GreenWine

Thanks all - with the help of Gemini I got into Ubuntu's inner workings and have verified that the NextDNS Cli tool which appears to capture all DNS queries from the system and gets everything to point to 127.0.0.1, then do it's magic. I could see in the conf file that DoT is enabled. So, it likely is Wine not quite up to speed.

So that one seems solved - but if anyone os getting the ability to benchmark DoT using Wine, please jump in.


#16

Steve

Steve

but if anyone os getting the ability to benchmark DoT using Wine, please jump in.
I'll have the 3rd release of DNSBv2 ready shortly. It has added a test and notification for WINE 8 and earlier.

WINE's development is on a "first of the year" update cadence. So I'm hoping that next month, when WINE 11.0 appears, it might resolve WINE's missing TLS support. That would be great! (But I'm actually not super hopeful, since Windows' Channel API is an unbelievable catastrophe.)


#17

GreenWine

GreenWine

I have set a calendar reminder to install Wine 11 and test the benchmark on new year's day :)


#18

Steve

Steve

I have set a calendar reminder to install Wine 11 and test the benchmark on new year's day :)
Generally, the annual releases are mid-month (mid-January).


#19

GreenWine

GreenWine

Using Steam and proton I can now add DoT nameservers, but they all stay red/dead. Using Proton 10 and latest version of the benchmark as of today.


#20

D

DanR

Using Steam and proton I can now add DoT nameservers, but they all stay red/dead
If you click the red icon in the UL corner of DNSB's main window, and get the main drop down menu, what do you see for the DOT protocol? Enabled or disabled? If it is not enabled then DNSB wile not benchmark DOT resolvers.


#21

GreenWine

GreenWine

If you click the red icon in the UL corner of DNSB's main window, and get the main drop down menu, what do you see for the DOT protocol? Enabled or disabled? If it is not enabled then DNSB wile not benchmark DOT resolvers.
Sorry for the delay.

Yes I checked in the system menu and enable DoT tests is enabled, but every DoT server is red after the inital startup checks, this is with both with the NextDNS service enabled or disabled. It is as if discussed further up, either the compatibility layer can't operate with DoT or Ubuntu can't. I have checked and Ubuntu does support it if setup in the resolv file, but that is just for the DNS settings you are using. It needs to be available system wide and maybe it is not.

Gemini seems to suggest I can force NextDNS to use DoT instead of DoH if I want to, but, I don't think this will help this particular issue, as again, it will just be my localhost service using DoT.

Screenshot From 2025-12-28 14-15-20.png


#22

P

PHolder

DoT tests is enabled
I don't think DNS over TLS is actually a well used protocol. DNS over HTTPS came along after, and seems to have the lions share of the "secure DNS" mind share. Part of the issue is probably what you're running into... there appear to be so many different implementations of TLS in different levels of support on different versions of Windows (and Windows emulation like WINE and Proton) that it makes it hard to ensure the necessary functionality is going to be present. I get where you might want to see this capability working in DNSB, but I would recommend against spending much time trying to make it work when it's probably not going to reward you with results to care about.


#23

GreenWine

GreenWine

I don't think DNS over TLS is actually a well used protocol. DNS over HTTPS came along after, and seems to have the lions share of the "secure DNS" mind share. Part of the issue is probably what you're running into... there appear to be so many different implementations of TLS in different levels of support on different versions of Windows (and Windows emulation like WINE and Proton) that it makes it hard to ensure the necessary functionality is going to be present. I get where you might want to see this capability working in DNSB, but I would recommend against spending much time trying to make it work when it's probably not going to reward you with results to care about.
DoH is fine for me, I just would like to see the full suite of tests running on Linux, I'm still not sure if anyone has so far.


#24

peterblaise

peterblaise

@GreenWine "... DoH is fine for me, I just would like to see the
full suite of tests running on Linux, I'm still not sure if anyone has so far ..."

Compare to one of my recent DNSBench 2 tests under Windows 7:

1767014476527.png


Messy, but I suppose this is what you are looking for.


#25

S

selig

I updated to wine 11, per the earlier suggestion, and now see why I suspect TLS isn't working

Code:
0548:fixme:winhttp:netconn_secure_connect SECBUFFER_EXTRA not supported
GnuTLS error: Decryption has failed.
0548:err:secur32:schan_DecryptMessage Returning 80090304
0580:fixme:secur32:get_cipher_algid unknown algorithm 23
0580:fixme:secur32:get_mac_algid unknown algorithm 200, cipher 23

There are a couple of other errors, but it seems like Wine is missing some features to support winhttp/schannel