=================================================================== RCS file: /cvsrepo/anoncvs/cvs/src/etc/unbound.conf,v retrieving revision 1.9 retrieving revision 1.10 diff -c -r1.9 -r1.10 *** src/etc/unbound.conf 2018/12/07 09:21:08 1.9 --- src/etc/unbound.conf 2018/12/07 11:54:04 1.10 *************** *** 1,4 **** ! # $OpenBSD: unbound.conf,v 1.9 2018/12/07 09:21:08 florian Exp $ server: interface: 127.0.0.1 --- 1,4 ---- ! # $OpenBSD: unbound.conf,v 1.10 2018/12/07 11:54:04 sthen Exp $ server: interface: 127.0.0.1 *************** *** 19,27 **** hide-identity: yes hide-version: yes ! # Uncomment to enable qname minimisation. ! # https://tools.ietf.org/html/rfc7816 ! # #qname-minimisation: yes # Enable DNSSEC validation. --- 19,25 ---- hide-identity: yes hide-version: yes ! # Uncomment to enable qname minimisation. RFC 7816 #qname-minimisation: yes # Enable DNSSEC validation. *************** *** 50,75 **** # #tcp-upstream: yes - # DNS64 options, synthesizes AAAA records for hosts that don't have - # them. For use with NAT64 (PF "af-to"). - # - #module-config: "dns64 validator iterator" - #dns64-prefix: 64:ff9b::/96 # well-known prefix (default) - #dns64-synthall: no - remote-control: control-enable: yes control-use-cert: no control-interface: /var/run/unbound.sock ! # Use an upstream forwarder (recursive resolver) for specific zones. ! # Example addresses given below are public resolvers valid as of 2014/03. # #forward-zone: # name: "." # use for ALL queries ! # forward-addr: 74.82.42.42 # he.net ! # forward-addr: 2001:470:20::2 # he.net v6 ! # forward-addr: 8.8.8.8 # google.com ! # forward-addr: 2001:4860:4860::8888 # google.com v6 ! # forward-addr: 208.67.222.222 # opendns.com # forward-first: yes # try direct if forwarder fails --- 48,61 ---- # #tcp-upstream: yes remote-control: control-enable: yes control-use-cert: no control-interface: /var/run/unbound.sock ! # Use an upstream forwarder (recursive resolver) for some or all zones. # #forward-zone: # name: "." # use for ALL queries ! # forward-addr: 192.0.2.53 # example address only # forward-first: yes # try direct if forwarder fails