From: Pieter Lexis Date: Tue, 8 Mar 2016 20:06:27 +0000 (+0100) Subject: Recursor: disable dnssec in the default config X-Git-Tag: dnsdist-1.0.0-beta1~135^2 X-Git-Url: https://granicus.if.org/sourcecode?a=commitdiff_plain;h=2b973889b37b4df33ce25cafa96a3322889432ac;p=pdns Recursor: disable dnssec in the default config This will be set to process after the dnssec implementation is more bug-free. --- diff --git a/docs/markdown/recursor/settings.md b/docs/markdown/recursor/settings.md index 51e4b5ed7..0b573a55f 100644 --- a/docs/markdown/recursor/settings.md +++ b/docs/markdown/recursor/settings.md @@ -169,7 +169,7 @@ cached. ## `dnssec` * One of `off`, `process`, `log-fail`, `validate`, String -* Default: `process` +* Default: `off` (**note**: was `process` until 4.0.0-alpha2) * Available since: 4.0.0 Set the mode for DNSSEC processing: diff --git a/pdns/pdns_recursor.cc b/pdns/pdns_recursor.cc index 929d54209..ccc45a169 100644 --- a/pdns/pdns_recursor.cc +++ b/pdns/pdns_recursor.cc @@ -2624,7 +2624,7 @@ int main(int argc, char **argv) ::arg().set("local-address","IP addresses to listen on, separated by spaces or commas. Also accepts ports.")="127.0.0.1"; ::arg().setSwitch("non-local-bind", "Enable binding to non-local addresses by using FREEBIND / BINDANY socket options")="no"; ::arg().set("trace","if we should output heaps of logging. set to 'fail' to only log failing domains")="off"; - ::arg().set("dnssec", "DNSSEC mode: off/process (default)/log-fail/validate")="process"; + ::arg().set("dnssec", "DNSSEC mode: off (default)/process/log-fail/validate")="off"; ::arg().set("daemon","Operate as a daemon")="no"; ::arg().setSwitch("write-pid","Write a PID file")="yes"; ::arg().set("loglevel","Amount of logging. Higher is more. Do not set below 3")="4";