]> git.ipfire.org Git - ipfire-2.x.git/commitdiff
unbound: Deactivate qname-minimization & harden-below-nxdomain
authorMichael Tremer <michael.tremer@ipfire.org>
Fri, 25 Nov 2016 17:45:39 +0000 (17:45 +0000)
committerMichael Tremer <michael.tremer@ipfire.org>
Fri, 25 Nov 2016 17:45:39 +0000 (17:45 +0000)
This causes trouble when you try to resolve a record like
a.b.blah.com where b.blah.com responds with NXDOMAIN. unbound
won't try to resolve a.b.blah.com because it is assumed that
everything longer than b.blah.com does not exist which is
probably not good usability.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
config/unbound/unbound.conf

index 3f724d8f76a81027a3a2b6542fb086a149010229..c9b01b8f47c3745545b41fc3e51d580bb8853a77 100644 (file)
@@ -42,7 +42,6 @@ server:
        # Privacy Options
        hide-identity: yes
        hide-version: yes
-       qname-minimisation: yes
        minimal-responses: yes
 
        # DNSSEC
@@ -56,7 +55,6 @@ server:
        harden-short-bufsize: no
        harden-large-queries: yes
        harden-dnssec-stripped: yes
-       harden-below-nxdomain: yes
        harden-referral-path: yes
        harden-algo-downgrade: no
        use-caps-for-id: no