Commit 370c6e0a authored by Evan Hunt's avatar Evan Hunt
Browse files

[master] add nsip-wait-recurse release note

parent 5ac42705
......@@ -12,7 +12,7 @@
4356. [func] Add the ability to specify whether to wait for
nameserver addresses to be looked up or not to
rpz with a new modifying directive 'nsip-wait-recurse'.
RPZ with a new modifying directive 'nsip-wait-recurse'.
[RT #35009]
4355. [func] "pkcs11-list" now displays the extractability
......@@ -649,6 +649,20 @@
on Linux is now supported.
A new <option>nsip-wait-recurse</option> directive has been
added to RPZ, specifying whether to look up unknown name server
IP addresses and wait for a response before applying RPZ-NSIP rules.
The default is <userinput>yes</userinput>. If set to
<userinput>no</userinput>, <command>named</command> will only
apply RPZ-NSIP rules to servers whose addresses are already cached.
The addresses will be looked up in the background so the rule can
be applied on subsequent queries. This improves performance when
the cache is cold, at the cost of temporary imprecision in applying
policy directives. [RT #35009]
Within the <option>response-policy</option> option, it is now
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment