unbound: move to tls-ystem-cert from tls-cert-bundle & disable qname minimization for DoT forward-zones

This commit is contained in:
Aminda Suomalainen 2024-04-17 16:01:38 +03:00
parent 6af465359d
commit 363be56010
Signed by: Mikaela
SSH Key Fingerprint: SHA256:CXLULpqNBdUKB6E6fLA1b/4SzG0HvKD19PbIePU175Q
7 changed files with 42 additions and 7 deletions

View File

@ -1,8 +1,13 @@
server: server:
# Debian ca-certificates location # Debian ca-certificates location
tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt #tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
# Fedora location # Fedora location
#tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem #tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
# Use system certificates no matter where they are
tls-system-cert: yes
# Quad9 says pointless performance impact on forwarders.
# https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization
qname-minimisation: no
# This list is for my travel laptop to have at least one DoT443 server # This list is for my travel laptop to have at least one DoT443 server
# which seems to be applied-privacy.net. They advice having multiple DoT servers # which seems to be applied-privacy.net. They advice having multiple DoT servers

View File

@ -3,9 +3,14 @@
server: server:
# Debian ca-certificates location # Debian ca-certificates location
tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt #tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
# ctrl.blog says this is the Fedora location # ctrl.blog says this is the Fedora location
#tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem #tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
# Use system certificates no matter where they are
tls-system-cert: yes
# Quad9 says pointless performance impact on forwarders.
# https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization
qname-minimisation: no
# Forward queries to # Forward queries to
forward-zone: forward-zone:

View File

@ -1,8 +1,13 @@
server: server:
# Debian ca-certificates location # Debian ca-certificates location
tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt #tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
# ctrl.blog says this is the Fedora location # ctrl.blog says this is the Fedora location
#tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem #tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
# Use system certificates no matter where they are
tls-system-cert: yes
# Quad9 says pointless performance impact on forwarders.
# https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization
qname-minimisation: no
forward-zone: forward-zone:
name: "." name: "."

View File

@ -7,9 +7,14 @@
server: server:
# Debian ca-certificates location # Debian ca-certificates location
tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt #tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
# Fedora # Fedora
#tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem #tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
# Use system certificates no matter where they are
tls-system-cert: yes
# Quad9 says pointless performance impact on forwarders.
# https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization
qname-minimisation: no
forward-zone: forward-zone:
name: "." name: "."

View File

@ -1,8 +1,13 @@
server: server:
# Debian ca-certificates location # Debian ca-certificates location
tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt #tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
# ctrl.blog says this is the Fedora location # ctrl.blog says this is the Fedora location
#tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem #tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
# Use system certificates no matter where they are
tls-system-cert: yes
# Quad9 says pointless performance impact on forwarders.
# https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization
qname-minimisation: no
forward-zone: forward-zone:
name: "." name: "."

View File

@ -3,9 +3,14 @@
server: server:
# Debian ca-certificates location # Debian ca-certificates location
tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt #tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
# Fedora location # Fedora location
#tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem #tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
# Use system certificates no matter where they are
tls-system-cert: yes
# Quad9 says pointless performance impact on forwarders.
# https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization
qname-minimisation: no
# DNS servers that have public button for flushing cache. Privacy not considered. # DNS servers that have public button for flushing cache. Privacy not considered.

View File

@ -1,8 +1,13 @@
server: server:
# Debian ca-certificates location # Debian ca-certificates location
tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt #tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt
# ctrl.blog says this is the Fedora location # ctrl.blog says this is the Fedora location
#tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem #tls-cert-bundle: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
# Use system certificates no matter where they are
tls-system-cert: yes
# Quad9 says pointless performance impact on forwarders.
# https://docs.quad9.net/Quad9_For_Organizations/DNS_Forwarder_Best_Practices/#disable-qname-minimization
qname-minimisation: no
forward-zone: forward-zone:
name: "." name: "."