Project

General

Profile

Actions

Todo #8411

closed

dnsmasq configuration needs changes for 2.79

Added by Jim Pingle about 6 years ago. Updated almost 6 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
DNS Forwarder
Target version:
Start date:
03/31/2018
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:

Description

Looks like host overrides might need some adjustments with dnsmasq 2.79. It is not in builds yet but once master switches to the new quarterly branch it will be there.

From the Change Log

Always return a SERVFAIL answer to DNS queries without the
recursion desired bit set, UNLESS acting as an authoritative
DNS server. This avoids a potential route to cache snooping.

And from FreeBSD-ports UPDATING:

20180319:
AFFECTS: users of dns/dnsmasq
AUTHOR:

Note that with dnsmasq 2.79, some parts of the interface have changed in an
incompatible way versus previous versions. This comprises changed recursion
behaviour, signature support, a change for SIGINT (vs. SIGHUP) behaviour.

Note especially that dnsmasq will no longer answer non-recursive queries
unless it is marked authoritative! Be sure to see the manual page for the
various --auth-* options, such as --auth-zone.

Please see the CHANGELOG that ships with dnsmasq for details.

Actions

Also available in: Atom PDF