Thu, Oct 24
Personally, I would just create a directory in /usr/local/share/ca-certificates/ for each CA certificate named the same as that part of the config node (ex: IPA.TRAE32566.ORG in my example), then run update-ca-certificates...I just don't know how to implement this myself.
Wed, Oct 23
Tue, Oct 22
Mon, Oct 21
Sun, Oct 20
Sat, Oct 19
Issue fixed by Github
Fri, Oct 18
Thu, Oct 17
Wed, Oct 16
Tue, Oct 15
@jvandenbroek fell free to cereate a PR for fix.
I was wondering why I couldn't get DSCP marked packets to match, just to discover that the code to make the rules are actually incorrect. OP gave the exact code - which I wish had noticed earlier - to make it work as intended. I can confirm it does work with both ipv4 and ipv6, with and without ECN bit set. So maybe you can use that code to update vyos/qos/base.py, which I currently run without problems:
Mon, Oct 14
Reported to netfilter bug tracker as https://bugzilla.netfilter.org/show_bug.cgi?id=1776