This seems to cause that some resolvers do not respond to queries any more until unbound falls back.
To ensure better DNS performance, we disabled this.
Signed-off-by: Michael Tremer michael.tremer@ipfire.org --- config/unbound/unbound.conf | 1 - 1 file changed, 1 deletion(-)
diff --git a/config/unbound/unbound.conf b/config/unbound/unbound.conf index c78ca1db7..3aab6ea46 100644 --- a/config/unbound/unbound.conf +++ b/config/unbound/unbound.conf @@ -42,7 +42,6 @@ server: # Hardening Options harden-large-queries: yes harden-referral-path: yes - use-caps-for-id: yes aggressive-nsec: yes
# TLS