]> git.ipfire.org Git - thirdparty/bind9.git/commit
Enable minimal ANY answers by default
authorOndřej Surý <ondrej@isc.org>
Wed, 28 Jan 2026 14:04:58 +0000 (15:04 +0100)
committerOndřej Surý <ondrej@isc.org>
Wed, 28 Jan 2026 14:38:18 +0000 (15:38 +0100)
commit0bebf8ee9d729a6e623cc16a8e08d40442073197
treef82152f16b0d2e1b677ac3b731afad8892b724aa
parent6c1bc49ec735844981ed9c08fd36d96e44d4de37
Enable minimal ANY answers by default

ANY queries are widely abused by attackers doing reflection attacks as
they return the largest answers.  Enable minimal ANY answers by default
to reduce the attack surface of the DNS servers.
30 files changed:
bin/include/defaultconfig.h
bin/tests/system/digdelv/ns2/named.conf.j2
bin/tests/system/digdelv/ns3/named.conf.j2
bin/tests/system/dnssec/ns1/named.conf.j2
bin/tests/system/dnssec/ns2/named.conf.j2
bin/tests/system/dnssec/ns3/named.conf.j2
bin/tests/system/dnssec/ns4/named.conf.j2
bin/tests/system/dnssec/ns5/named.conf.j2
bin/tests/system/dnssec/ns6/named.conf.j2
bin/tests/system/dnssec/ns9/named.conf.j2
bin/tests/system/resolver/ns1/named.conf.j2
bin/tests/system/resolver/ns11/named.conf.j2
bin/tests/system/resolver/ns4/named.conf.j2
bin/tests/system/resolver/ns5/named.conf.j2
bin/tests/system/resolver/ns6/named.conf.j2
bin/tests/system/resolver/ns7/named.conf.j2
bin/tests/system/resolver/ns9/named.conf.j2
bin/tests/system/rpz/ns1/named.conf.j2
bin/tests/system/rpz/ns10/named.conf.j2
bin/tests/system/rpz/ns2/named.conf.j2
bin/tests/system/rpz/ns3/named.conf.j2
bin/tests/system/rpz/ns4/named.conf.j2
bin/tests/system/rpz/ns5/named.conf.j2
bin/tests/system/rpz/ns6/named.conf.j2
bin/tests/system/rpz/ns7/named.conf.j2
bin/tests/system/rpz/ns8/named.conf.j2
bin/tests/system/rpz/ns9/named.conf.j2
bin/tests/system/rpzextra/ns2/named.conf.j2
bin/tests/system/rpzextra/ns3/named.conf.j2
doc/arm/reference.rst