|
@ -1,4 +1,4 @@ |
|
|
# $OpenBSD: unbound.conf,v 1.19 2019/11/07 15:46:37 sthen Exp $ |
|
|
|
|
|
|
|
|
# $OpenBSD: unbound.conf,v 1.20 2020/06/21 16:59:45 sthen Exp $ |
|
|
|
|
|
|
|
|
server: |
|
|
server: |
|
|
interface: 127.0.0.1 |
|
|
interface: 127.0.0.1 |
|
@ -19,12 +19,12 @@ server: |
|
|
hide-identity: yes |
|
|
hide-identity: yes |
|
|
hide-version: yes |
|
|
hide-version: yes |
|
|
|
|
|
|
|
|
# Perform DNSSEC validation. Comment out the below option to disable. |
|
|
|
|
|
|
|
|
# Perform DNSSEC validation. |
|
|
# |
|
|
# |
|
|
auto-trust-anchor-file: "/var/unbound/db/root.key" |
|
|
auto-trust-anchor-file: "/var/unbound/db/root.key" |
|
|
val-log-level: 2 |
|
|
val-log-level: 2 |
|
|
|
|
|
|
|
|
# Uncomment to synthesize NXDOMAINs from DNSSEC NSEC chains |
|
|
|
|
|
|
|
|
# Synthesize NXDOMAINs from DNSSEC NSEC chains. |
|
|
# https://tools.ietf.org/html/rfc8198 |
|
|
# https://tools.ietf.org/html/rfc8198 |
|
|
# |
|
|
# |
|
|
aggressive-nsec: yes |
|
|
aggressive-nsec: yes |
|
|