]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
Remove dnspriv example from the contrib directory
authorOndřej Surý <ondrej@sury.org>
Mon, 20 Sep 2021 10:44:49 +0000 (12:44 +0200)
committerOndřej Surý <ondrej@sury.org>
Mon, 20 Sep 2021 20:26:17 +0000 (22:26 +0200)
BIND 9 has now native DoH support, so there's no need to have nginx
proxy example in the contrib/ directory.

contrib/README
contrib/dnspriv/README.md [deleted file]
contrib/dnspriv/named.conf [deleted file]
contrib/dnspriv/nginx.conf [deleted file]
util/copyrights

index d02717b036401793358f6478558d5fb7a63a6c05..0cdedc74a9c9939f2944f446dbecda842ef1ac59 100644 (file)
@@ -8,11 +8,6 @@ be fixed as time permits.
       named and restarts it in the event of a crash, 'zone-edit'
       which enables editing of a dynamic zone, and others.
 
-    - dnspriv/
-
-      Sample configuration for setting up a DNS-over-TLS server
-      using BIND with Nginx as a TLS proxy.
-
     - kasp/
 
       Scripts for converting key and signature policies from OpenDNSSEC
diff --git a/contrib/dnspriv/README.md b/contrib/dnspriv/README.md
deleted file mode 100644 (file)
index 8fa6795..0000000
+++ /dev/null
@@ -1,23 +0,0 @@
-<!--
- - Copyright (C) Internet Systems Consortium, Inc. ("ISC")
- -
- - This Source Code Form is subject to the terms of the Mozilla Public
- - License, v. 2.0. If a copy of the MPL was not distributed with this
- - file, You can obtain one at http://mozilla.org/MPL/2.0/.
- -
- - See the COPYRIGHT file distributed with this work for additional
- - information regarding copyright ownership.
--->
-### DNS Privacy in BIND
-
-This directory contains sample configuration files to enable BIND,
-with Nginx as a TLS proxy, to provide DNS over TLS.
-
-`named.conf` configures a validating recursive name server to listen
-on the localhost address at port 8853.
-
-`nginx.conf` configures a TLS proxy to listen on port 853 and
-forward queries and responses to `named`.
-
-For more information, please see
-[https://dnsprivacy.org/wiki/](https://dnsprivacy.org/wiki/)
diff --git a/contrib/dnspriv/named.conf b/contrib/dnspriv/named.conf
deleted file mode 100644 (file)
index 12d07a3..0000000
+++ /dev/null
@@ -1,18 +0,0 @@
-/*
- * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
- *
- * This Source Code Form is subject to the terms of the Mozilla Public
- * License, v. 2.0. If a copy of the MPL was not distributed with this
- * file, You can obtain one at http://mozilla.org/MPL/2.0/.
- *
- * See the COPYRIGHT file distributed with this work for additional
- * information regarding copyright ownership.
- */
-
-options {
-       listen-on port 8853 { 127.0.0.1; };
-       allow-query { localhost; };
-       recursion yes;
-       dnssec-validation auto;
-       tcp-clients 1024;
-};
diff --git a/contrib/dnspriv/nginx.conf b/contrib/dnspriv/nginx.conf
deleted file mode 100644 (file)
index 763ff35..0000000
+++ /dev/null
@@ -1,41 +0,0 @@
-# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
-#
-# This Source Code Form is subject to the terms of the Mozilla Public
-# License, v. 2.0. If a copy of the MPL was not distributed with this
-# file, you can obtain one at https://mozilla.org/MPL/2.0/.
-#
-# See the COPYRIGHT file distributed with this work for additional
-# information regarding copyright ownership.
-
-# uncomment to choose an appropriate UID/GID; default is 'nobody'
-# user bind bind;
-
-worker_processes auto;
-pid /var/run/nginx.pid;
-
-events {
-    worker_connections 1024;
-    multi_accept on;
-}
-
-stream {
-    upstream dns_tcp_servers {
-       server 127.0.0.1:8853;
-    }
-
-    server {
-       listen 853 ssl;
-       proxy_pass dns_tcp_servers;
-
-       # update to a suitable SSL certificate (e.g. from LetsEncrypt),
-       # and uncomment the following lines:
-       # ssl_certificate       /etc/nginx/lego/certificates/<cert>.crt;
-       # ssl_certificate_key   /etc/nginx/lego/certificates/<cert>.key;
-
-       ssl_protocols         TLSv1.2;
-       ssl_ciphers           ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
-       ssl_session_tickets   on;
-       ssl_session_timeout   4h;
-       ssl_handshake_timeout 30s;
-    }
-}
index 4d098720b6962d986ee9c6b36f719d0761a50fec..1e81d475e7b8c66d0ba42a3562ac35da7fb2bfc3 100644 (file)
 ./contrib/dlz/modules/wildcard/README          X       2013,2018,2019,2020,2021
 ./contrib/dlz/modules/wildcard/dlz_wildcard_dynamic.c  X       2013,2015,2016,2018,2019,2020,2021
 ./contrib/dlz/modules/wildcard/testing/named.conf      X       2013,2018,2019
-./contrib/dnspriv/nginx.conf                   SH      2017,2018,2019
 ./contrib/kasp/README                          X       2020,2021
 ./contrib/kasp/kasp.xml                                X       2020,2021
 ./contrib/kasp/policy.good                     X       2020,2021