- A systemd service
- AdHole starts with the machine and restarts on its own 5 seconds after a crash.
- Port 53, freed
- On Ubuntu, Fedora and others, systemd-resolved’s local listener (127.0.0.53) holds port 53.
setup turns it off with a small configuration file and points /etc/resolv.conf at your router’s servers, so the machine keeps resolving names. If systemd-resolved knows no server from your router, setup stops rather than cut your connection.
- This computer’s DNS
- Pointed at AdHole first, with your router behind it as a fallback: through systemd-resolved, or through NetworkManager where it manages DNS. If neither does,
setup tells you to set it by hand: 127.0.0.1, then your router’s address.
- The certificate
- Created on this machine, in the system store, and in Chrome’s and Firefox’s stores when
certutil is present. Its private key never leaves the machine and only administrators can read it.
- The desktop proxy
- Under GNOME and KDE, the automatic proxy configuration script. Browsers go through AdHole, and go direct if it doesn’t answer.
- The firewall
- If ufw or firewalld is active: port 53 opened to your local network only, and port 67 for the address server AdHole can provide (off by default). Rules you keep directly in nftables or iptables are left alone.
- Menu and command
- “AdHole” in the applications menu, and the
adhole command.