From 4bbe035ddf18f7e539b683f09b227f91ff9c485e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20=C5=A0pa=C4=8Dek?= Date: Mon, 27 Mar 2023 15:14:21 +0200 Subject: [PATCH] Clarify qname-minimization relaxed in the ARM Leading underscore in qname confused some users, and it was not documented. (cherry picked from commit 02430a72630b66875fcfe5f44cc1384fa2fdd423) --- doc/arm/reference.rst | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/doc/arm/reference.rst b/doc/arm/reference.rst index 703663d0ba..ebf1f0b30d 100644 --- a/doc/arm/reference.rst +++ b/doc/arm/reference.rst @@ -1160,14 +1160,20 @@ default is used. effective user ID of the ``named`` process. ``qname-minimization`` - This option controls QNAME minimization behavior in the BIND - resolver. When set to ``strict``, BIND follows the QNAME + When this is set to ``strict``, BIND follows the QNAME minimization algorithm to the letter, as specified in :rfc:`7816`. + Setting this option to ``relaxed`` causes BIND to fall back to normal (non-minimized) query mode when it receives either NXDOMAIN or other unexpected responses (e.g., SERVFAIL, improper zone cut, - REFUSED) to a minimized query. ``disabled`` disables QNAME - minimization completely. The current default is ``relaxed``, but it + REFUSED) to a minimized query. A resolver can use a leading + underscore, like ``_.example.com``, in an attempt to improve + interoperability. (See :rfc:`7816` section 3.) + + ``disabled`` disables QNAME minimization completely. + ``off`` is a synonym for ``disabled``. + + The current default is ``relaxed``, but it may be changed to ``strict`` in a future release. ``tkey-gssapi-keytab``