From: Pieter Lexis Date: Fri, 18 Jan 2019 16:24:50 +0000 (+0100) Subject: rec: Update docs wrt trustanchor queries X-Git-Tag: dnsdist-1.4.0-rc1~108^2~5 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=f19a673ba582f5011f72a911b1dceef4378b8603;p=thirdparty%2Fpdns.git rec: Update docs wrt trustanchor queries --- diff --git a/pdns/recursordist/docs/dnssec.rst b/pdns/recursordist/docs/dnssec.rst index 6722e0bdba..f7b57e354f 100644 --- a/pdns/recursordist/docs/dnssec.rst +++ b/pdns/recursordist/docs/dnssec.rst @@ -164,7 +164,7 @@ Negative trust anchors (defined in :rfc:`7646`) can be used to temporarily disab This can be done when e.g. a TLD or high-traffic zone goes bogus. Note that it is good practice to verify that this is indeed the case and not because of malicious actions. -Current trust anchors can be queried from the recursor by sending a query for "negativetrustanchor.server CH TXT". +Current negative trust anchors can be queried from the recursor by sending a query for "negativetrustanchor.server CH TXT". This query will (if :ref:`setting-allow-trust-anchor-query` is enabled) return a TXT record per negative trust-anchor in the format ``"DOMAIN [REASON]"``. To configure a negative trust anchor, use the ``addNTA()`` function in the :ref:`setting-lua-config-file` and restart the recursor. diff --git a/pdns/recursordist/docs/settings.rst b/pdns/recursordist/docs/settings.rst index fb5bc1afd7..ae05e1d1bf 100644 --- a/pdns/recursordist/docs/settings.rst +++ b/pdns/recursordist/docs/settings.rst @@ -58,7 +58,7 @@ Useful for mitigating ANY reflection attacks. ``allow-trust-anchor-query`` ---------------------------- -.. versionadded:: 4.1.0 +.. versionadded:: 4.2.0 - Boolean - Default: yes