Deprecate 'dnssec-must-be-secure' option

The dnssec-must-be-secure feature was added in the early days of BIND 9
and DNSSEC and it makes sense only as a debugging feature.

Remove the feature to simplify the code.
This commit is contained in:
Ondřej Surý
2023-09-04 13:08:48 +02:00
parent eac0a4b3ed
commit 9e0b348a2b
5 changed files with 9 additions and 4 deletions

View File

@@ -26,6 +26,8 @@ options {
use-v6-udp-ports { range 1024 65535; };
avoid-v4-udp-ports { range 1 1023; };
avoid-v6-udp-ports { range 1 1023; };
dnssec-must-be-secure mustbesecure.example yes;
};
trusted-keys {