dnsmasq: I don't care about breaking OpenDNS

OpenDNS should care about breaking me.
This commit is contained in:
Aminda Suomalainen 2017-01-12 12:54:52 +02:00
parent 954a3b7b93
commit 36b1544606
No known key found for this signature in database
GPG Key ID: 0C207F07B2F32B67
1 changed files with 7 additions and 3 deletions

View File

@ -9,6 +9,10 @@ listen-address=::1,127.0.0.1
# dnsmasq-base on Ubuntu
dnssec
# Verify that DNSSEC is not stripped, disabled thanks to OpenDNS, to be
# enabled if they ever stop that behaviour (I hope).
#dnssec-check-unsigned
# Verify that DNSSEC is not stripped. This breaks OpenDNS, but at time
# of writing I don't care about OpenDNS as them not supporting DNSSEC is
# their issue, not my issue.
# https://support.opendns.com/hc/en-us/community/posts/220015487-Implement-DNSSEC
# https://support.opendns.com/hc/en-us/community/posts/220018307-DNSSEC-on-resolver-side
# https://support.opendns.com/hc/en-us/community/posts/220022287-support-for-DNSSEC
dnssec-check-unsigned