
BootAble – FreeDOS boot testing freeware
To obtain direct, low-level access to a system's mass storage drives, SpinRite runs under a GRC-customized version of FreeDOS which has been modified to add compatibility with all file systems. In order to run SpinRite it must first be possible to boot FreeDOS.
GRC's “BootAble” freeware allows anyone to easily create BIOS-bootable media in order to workout and confirm the details of getting a machine to boot FreeDOS through a BIOS. Once the means of doing that has been determined, the media created by SpinRite can be booted and run in the same way.
The participants here, who have taken the time to share their knowledge and experience, their successes and some frustrations with booting their computers into FreeDOS, have created a valuable knowledgebase which will benefit everyone who follows.
You may click on the image to the right to obtain your own copy of BootAble. Then use the knowledge and experience documented here to boot your computer(s) into FreeDOS. And please do not hesitate to ask questions – nowhere else can better answers be found.
(You may permanently close this reminder with the 'X' in the upper right.)
I think your system needs to have DNS over TLS (DOT) enabled.Is there something I am missing to enable the TLS tests?
Thanks! I can confirm that I can set a DoT DNS server on my computer, but I am not sure what the test is looking at to trigger this error. It prevents me from testing any DoT server.I think your system needs to have DNS over TLS (DOT) enabled.
It seems a bit complicated: https://duckduckgo.com/?q=DNS over TLS Winsows 11&t=newext&atb=v340-1&ia=web
I can run it. But, does it matter that this is testing in the browser and DNSB v2 is running on my Desktop?What does this page show for you?
TLS Client Test - TLS Fingerprinting
Check your browser's supported SSL/TLS protocols. Inspect TLS ClientHello, supported cipher suites, TLS extensions, test ECH support. Identify weak or insecure options, generate a JA3/JA4 TLS fingerprint, and test how the browser handles insecure mixed content.browserleaks.com
Gotcha, Mine looks exactly like yours.Regardless of the options set on my Windows, I want to test if they
actually work and are 'seen' in the real world of browsing,
So, at https://browserleaks.com/tls for example, I get:
Protocol Support
TLS 1.3 ✔Enabled
TLS 1.2 ✔Enabled
TLS 1.1 ✖Disabled (Good)
TLS 1.0 ✖Disabled (Good)
If I had TLS1.2 set, but it wasn't 'seen' out there, then I'd need to
troubleshoot.
I apologize, what should I be trying next?Ah, so after a power-cycle reboot of everything, including our
modem/router and all switches ;-) . . . DNSBench 2 then says ... ?
And in Safe Mode with Networking?
I can confirm:Are you using the latest commercial release 4?
2.0.9486.1
See https://www.grc.com/dns/version-history.htm
Redownload DNSBench 2 and test the new download.
Resolved = you win.
'Problem' still there = keep troubleshooting.
- - - - -
Everyone has personal troubleshooting preferences, especially if they
have seen the problem before ( which for me was resolved by
updating TLS protocols that were missing ).
I suggest two troubleshooting schemes:
duplicate and documentdivide and conquer
So if you start from scratch, power-cycle everything, and try again,
even try another computer, does the problem stay, or is it resolved?
Resolved = you win.
'Problem' still there = keep troubleshooting.
Then change something, such as rebooting into Safe Mode with
Networking *.
Resolved = something in real mode is inserting itself, thus starts
the hunt.
'Problem' still there = keep troubleshooting.
- - - - -
* Google suggests: To reboot Windows 11 into Safe Mode withNetworking, hold down the Shift key while selectingStart > Power > Restart.Once the PC restarts to a blue menu, navigate toTroubleshoot > Advanced options > Startup Settings > Restart,This video demonstrates how to restart your computer in Safe Modewith networking:
Alternative Methods:
- System Configuration (msconfig): Press , type , go to the Boot tab,
select Safe boot with Network, and restart.- Command Prompt: Open Command Prompt as administrator, run ,
then restart. [1, 4, 5]Exiting Safe Mode:Restart your computer normally. If you used , youmust go back and uncheck "Safe boot" to prevent booting into Safe[2][3][5][6]
That's understandable, I'd just like to be able to test DoH and DoT, so having it working would be nice. Thanks!I'll grant you it would be nice to get to the bottom of things wrt DoT but Steve did run into difficulties getting it working on some machines anyway, and I believe that is because it is sort of a black sheep. DoH seems to have mostly supplanted it, near as I can tell, so unless you're really set on getting DoT working for a specific reason, I think I'd choose DoH anyway.
I did try changing the benchmark speed to 9999 and 123456, and they did get rid of the TLS warning. But, all of the TLS severs show as unable to test.Try slowing DNSBench 2 R4 down:
Via menus:
Alt SpacebarChange Benchmark Speed: 20 msec[ 9999 ] msec per resolverAccept
View attachment 1981
9999 milliseconds = 9.999 seconds delay between queries
- - - - -
Or via command line:
DNSBENCH.EXE /PAUSE 123456
... where 123456 is any number of ms / msec / miliseconds to delay
between queries.
123456 milliseconds = 2.0576 minutes delay between queries
I've run 5 minutes and longer delays to empower getting results
through some systems.
- - - - -
If either of those gives joy, then whatever is responding to TLS in
your system is really ... burdened and not very responsive.
- - - - -
Alternatively, maybe it's a particular DoT getting caught, so try:
delete all,toggle off IPv4, IPv6, and DoH,load System to get DoT only,try a Benchmark
also
delete all but one DoT,try a Benchmark- - - - -
Anything?
So I just tested on a Ubuntu 24.04 VM I have setup, and I got the same result with all TLS servers unable to test. I even tried changing the DNS in my router from just using unbound resolver mode to using it in forwarding mode to Quad 9 TLS, and I still could not get the TLS servers to show up as available to test. Thanks!I did try changing the benchmark speed to 9999 and 123456, and they did get rid of the TLS warning. But, all of the TLS servers show as unable to test
Wow.
Movement, but no resolution.
Any ideas, anybody?
Do you have any other computers, even a loaner from a friend, that
you can test through your modem/router?
Can you test your OC through someone else's ISP?
We're trying to isolate the source of the block:
- your PC
- your modem/router
- your ISP.
What if . . . you change your DNS servers in your PC and or in your
modem/router to known TLS-compatible DNS servers?
So, what are your DNS servers now?
Try changing them to, as Google AI-assisted search suggests today 2026-03-15:
The public DNS servers with the best reputation for robust, secure, and fast DNS-over-TLS DoT support are Cloudflare, Google, Quad9, and CleanBrowsing. These providers specialize in DNS privacy, supporting TLS 1.3 and offering high uptime to prevent eavesdropping and hijacking.
Top Public DNS Servers for TLS (DoT/DoH) • Cloudflare 1.1.1.11.0.0.1Highly regarded for speed and strict privacy policies, encrypting all queries via DoT and DoH.
• Google Public DNS8.8.8.88.8.4.4Offers very fast, reliable, and secure resolution, supporting TLS 1.3 and extensive DNSSEC validation.
• Quad99.9.9.9Focuses heavily on security, blocking known malicious sites while providing DoT for privacy.
• CleanBrowsing: Popular for its focus on security and privacy, including specialized family filtering options.
• AdGuard DNS: Specializes in blocking ads, trackers, and malicious websites using secure, encrypted DNS. These providers allow you to use strict or opportunistic DoT to authenticate the server, preventing tampering.
Yeah, Wine has trouble supplying the necessary crypto. Newer Wine versions may work better, but it's still better to go for DoH for better/working support in any version of Windows.Ubuntu 24.04
I think the default version of Wine with Ubuntu 24.04 is Wine 8 which does not support the necessary crypto. It has been noted before that you need at least Wine 9.0 for DNS over TLS and this is not in the Ubuntu repositories yet. You should be able to install Wine 9.0+ manually.Yeah, Wine has trouble supplying the necessary crypto. Newer Wine versions may work better, but it's still better to go for DoH for better/working support in any version of Windows.