Attention is currently required from: d12fk, flichtenheld, plaisthos. selvanair has posted comments on this change by selvanair. ( http://gerrit.openvpn.net/c/openvpn/+/1643?usp=email )
Change subject: dns: correctly handle dnssec settings ...................................................................... Patch Set 1: (1 comment) File include/openvpn-msg.h: http://gerrit.openvpn.net/c/openvpn/+/1643/comment/1e00a0b2_cb21ee82?usp=email : PS1, Line 114: nrpt_dnssec_required = 1 << 1, > NRPT seems to have two separate settings `DnsSecEnabled` and > `DnsSecValidationRequired`. […] Correct.. I interpret DNSSecEnabled to mean optional as that causes the resolver to set DO flag in queries but not enforce validation. But unsure what use is that. Its not true "opportunistic" DNSSEC if that's what optional means. A minimal patch that ignores documentation mismatches, and other niceties should be possible. Let me see.. -- To view, visit http://gerrit.openvpn.net/c/openvpn/+/1643?usp=email To unsubscribe, or for help writing mail filters, visit http://gerrit.openvpn.net/settings?usp=email Gerrit-MessageType: comment Gerrit-Project: openvpn Gerrit-Branch: master Gerrit-Change-Id: Id514b06223cb55295c92b1fa6727f03d6e06befe Gerrit-Change-Number: 1643 Gerrit-PatchSet: 1 Gerrit-Owner: selvanair <[email protected]> Gerrit-Reviewer: flichtenheld <[email protected]> Gerrit-Reviewer: plaisthos <[email protected]> Gerrit-CC: d12fk <[email protected]> Gerrit-CC: openvpn-devel <[email protected]> Gerrit-Attention: plaisthos <[email protected]> Gerrit-Attention: flichtenheld <[email protected]> Gerrit-Attention: d12fk <[email protected]> Gerrit-Comment-Date: Wed, 29 Apr 2026 20:52:34 +0000 Gerrit-HasComments: Yes Gerrit-Has-Labels: No Comment-In-Reply-To: flichtenheld <[email protected]> Comment-In-Reply-To: d12fk <[email protected]> Comment-In-Reply-To: selvanair <[email protected]>
_______________________________________________ Openvpn-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/openvpn-devel
