These are meanwhile set by Unbound upstream as well, so there is no need
to do things twice here.
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
prefetch: yes
prefetch-key: yes
- # Randomise any cached responses
- rrset-roundrobin: yes
-
# Privacy Options
hide-identity: yes
hide-version: yes
# TLS
tls-cert-bundle: /etc/ssl/certs/ca-bundle.crt
- # EDNS Buffer Size (#12240)
- edns-buffer-size: 1232
-
# Harden against DNS cache poisoning
unwanted-reply-threshold: 1000000