Complete work to allow DNSSEC validation with private DNS servers.

This commit is contained in:
Simon Kelley
2016-01-16 18:39:54 +00:00
parent bb58f63ce5
commit 92be34a407
3 changed files with 54 additions and 18 deletions

View File

@@ -405,7 +405,10 @@ xxx.internal.thekelleys.org.uk at 192.168.1.1 then giving the flag
.B -S /internal.thekelleys.org.uk/192.168.1.1
will send all queries for
internal machines to that nameserver, everything else will go to the
servers in /etc/resolv.conf. An empty domain specification,
servers in /etc/resolv.conf. DNSSEC validation is turned off for such
private nameservers, UNLESS a
.B --trust-anchor
is specified for the domain in question. An empty domain specification,
.B //
has the special meaning of "unqualified names only" ie names without any
dots in them. A non-standard port may be specified as