]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
arm: add why when to set 'require-server-cookie yes;'
authorMark Andrews <marka@isc.org>
Thu, 24 Oct 2019 23:06:56 +0000 (10:06 +1100)
committerOndřej Surý <ondrej@sury.org>
Thu, 31 Oct 2019 14:04:01 +0000 (09:04 -0500)
doc/arm/Bv9ARM-book.xml

index 3051411d74220c259745c7f56bb074556ec4e644..c6f6ec18356e8876913045f3d0b60a98c03650f3 100644 (file)
@@ -6011,6 +6011,12 @@ options {
                  server cookie.
                  The default is <userinput>no</userinput>.
                </para>
+               <para>
+                 Set this to <userinput>yes</userinput> to test that DNS
+                 COOKIE clients correctly handle BADCOOKIE or if you are
+                 getting a lot of forged DNS requests with DNS COOKIES
+                 present.
+               </para>
              </listitem>
            </varlistentry>