summaryrefslogtreecommitdiffstats
path: root/usr.sbin/unbound
Commit message (Collapse)AuthorAgeFilesLines
* MFH (r271255): fix parsing of ipv6 nameserver linesdes2014-09-181-1/+1
| | | | Approved by: re (kib)
* MFH (r266114, r266138): upgrade to latest ldns and unbounddes2014-07-291-3/+62
| | | | | | | | | | | MFH (r266139-r266143, r266145, r266149, r266150): fix props MFH (r266179, r266180, r266193, r266238, r266777): misc cleanup MFH (r266863): create and use /var/unbound/conf.d MFH (r268839): import unblock-lan-zones patch from upstream MFH (r268840): fix reverse lookups on private networks MFH (r268883): avoid spamming source tree during build PR: 190739 (for r268883)
* Prevent resolvconf from updating /etc/resolv.conf. As Jakob Schlyterdes2013-09-231-5/+3
| | | | | | | | | | pointed out, having additional nameservers listed in /etc/resolv.conf can break DNSSEC verification by providing a false positive if unbound returns SERVFAIL due to an invalid signature. The downside is that the domain / search path won't get updated either, but we can live with that. Approved by: re (blanket)
* Ensure that resolvconf(8) preserves the edns0 setting.des2013-09-231-0/+1
| | | | Approved by: re (blanket)
* Add a setup script for unbound(8) called local-unbound-setup. Itdes2013-09-233-0/+364
| | | | | | | | | | | | | | | | | | | | | | | | | generates a configuration suitable for running unbound as a caching forwarding resolver, and configures resolvconf(8) to update unbound's list of forwarders in addition to /etc/resolv.conf. The initial list is taken from the existing resolv.conf, which is rewritten to point to localhost. Alternatively, a list of forwarders can be provided on the command line. To assist this script, add an rc.subr command called "enabled" which does nothing except return 0 if the service is enabled and 1 if it is not, without going through the usual checks. We should consider doing the same for "status", which is currently pointless. Add an rc script for unbound, called local_unbound. If there is no configuration file, the rc script runs local-unbound-setup to generate one. Note that these scripts place the unbound configuration files in /var/unbound rather than /etc/unbound. This is necessary so that unbound can reload its configuration while chrooted. We should probably provide symlinks in /etc. Approved by: re (blanket)
* Set NO_WERROR for unbound until I can figure out how to unbreak thedes2013-09-151-0/+2
| | | | | | non-clang build. Approved by: re (blanket)
* Build and install the Unbound caching DNS resolver daemon.des2013-09-156-0/+78
Approved by: re (blanket)
OpenPOWER on IntegriCloud