mirror of
https://github.com/Dasharo/systemd.git
synced 2026-03-06 15:02:31 -08:00
man/resolve: update DNSSEC description
This behavior was changed.
Fixes: 9c47b33444 ("resolved: enable DNS proxy mode if client wants DNSSEC")
This commit is contained in:
committed by
Luca Boccassi
parent
5e418fe32a
commit
4e17de7fee
@@ -170,9 +170,7 @@
|
||||
downgrade to non-DNSSEC mode by synthesizing a DNS response that suggests DNSSEC was not
|
||||
supported.</para>
|
||||
|
||||
<para>If set to false, DNS lookups are not DNSSEC validated. In this mode, or when set to
|
||||
<literal>allow-downgrade</literal> and the downgrade has happened, the resolver becomes
|
||||
security-unaware and all forwarded queries have DNSSEC OK (DO) bit unset.</para>
|
||||
<para>If set to false, DNS lookups are not DNSSEC validated.</para>
|
||||
|
||||
<para>Note that DNSSEC validation requires retrieval of additional DNS data, and thus results in a
|
||||
small DNS lookup time penalty.</para>
|
||||
|
||||
Reference in New Issue
Block a user