This is an automated email from the git hooks/post-receive script. It was generated because a ref change was pushed to the repository containing the project "IPFire 2.x development tree".
The branch, next has been updated via 86e9d04bfb73eb256682a567e187fe1e5cdcc3ca (commit) from bc4a68812bb131be6a8413f69909bf6a3d5a89a2 (commit)
Those revisions listed above that are new to this repository have not appeared on any other notification email; so we list those revisions in full, below.
- Log ----------------------------------------------------------------- commit 86e9d04bfb73eb256682a567e187fe1e5cdcc3ca Author: Michael Tremer michael.tremer@ipfire.org Date: Fri Nov 25 17:45:39 2016 +0000
unbound: Deactivate qname-minimization & harden-below-nxdomain
This causes trouble when you try to resolve a record like a.b.blah.com where b.blah.com responds with NXDOMAIN. unbound won't try to resolve a.b.blah.com because it is assumed that everything longer than b.blah.com does not exist which is probably not good usability.
Signed-off-by: Michael Tremer michael.tremer@ipfire.org
-----------------------------------------------------------------------
Summary of changes: config/unbound/unbound.conf | 2 -- 1 file changed, 2 deletions(-)
Difference in files: diff --git a/config/unbound/unbound.conf b/config/unbound/unbound.conf index 3f724d8..c9b01b8 100644 --- a/config/unbound/unbound.conf +++ b/config/unbound/unbound.conf @@ -42,7 +42,6 @@ server: # Privacy Options hide-identity: yes hide-version: yes - qname-minimisation: yes minimal-responses: yes
# DNSSEC @@ -56,7 +55,6 @@ server: harden-short-bufsize: no harden-large-queries: yes harden-dnssec-stripped: yes - harden-below-nxdomain: yes harden-referral-path: yes harden-algo-downgrade: no use-caps-for-id: no
hooks/post-receive -- IPFire 2.x development tree