From f24887cd86daf726b2248e9f84ac19311bb8b7ba Mon Sep 17 00:00:00 2001 From: Remi Gacogne Date: Wed, 24 Feb 2021 11:34:19 +0100 Subject: [PATCH] rec: Enable the aggressive NSEC cache by default, if DNSSEC is enabled --- pdns/pdns_recursor.cc | 6 +++--- pdns/recursordist/docs/settings.rst | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/pdns/pdns_recursor.cc b/pdns/pdns_recursor.cc index c0f713f491..c4a34be77e 100644 --- a/pdns/pdns_recursor.cc +++ b/pdns/pdns_recursor.cc @@ -4746,11 +4746,11 @@ static int serviceMain(int argc, char*argv[]) s_addExtendedResolutionDNSErrors = ::arg().mustDo("extended-resolution-errors"); if (::arg().asNum("aggressive-nsec-cache-size") > 0) { - if (g_dnssecmode == DNSSECMode::ValidateAll || g_dnssecmode == DNSSECMode::ValidateForLog) { + if (g_dnssecmode == DNSSECMode::ValidateAll || g_dnssecmode == DNSSECMode::ValidateForLog || g_dnssecmode == DNSSECMode::Process) { g_aggressiveNSECCache = make_unique(::arg().asNum("aggressive-nsec-cache-size")); } else { - g_log<