From: Graham Hayes Date: Thu, 9 Jul 2015 17:18:30 +0000 (+0100) Subject: Fix out-of-zone-additional-processing documentation X-Git-Tag: dnsdist-1.0.0-alpha1~248^2~58^2~20^2 X-Git-Url: https://granicus.if.org/sourcecode?a=commitdiff_plain;h=b6a59cdcfec5fd25293d0cbd1249e1c363865170;p=pdns Fix out-of-zone-additional-processing documentation Docs indicate that it defaults to "no", while it actually defaults to "yes". --- diff --git a/docs/markdown/authoritative/settings.md b/docs/markdown/authoritative/settings.md index dff03e258..767985036 100644 --- a/docs/markdown/authoritative/settings.md +++ b/docs/markdown/authoritative/settings.md @@ -507,13 +507,16 @@ or ALSO-NOTIFY metadata always receive AXFR NOTIFY. ## `out-of-zone-additional-processing` * Boolean -* Default: no +* Default: yes Do out of zone additional processing. This means that if a malicious user adds a '.com' zone to your server, it is not used for other domains and will not contaminate answers. Do not enable this setting if you run a public DNS service with untrusted users. +The docs had previously indicated that the default was "no", but the default has +been "yes" since 2005. + ## `pipebackend-abi-version` * Integer * Default: 1