Bugzilla – Bug 1127
Stricter qname minimisation
Last modified: 2016-10-14 14:02:21 CEST
Currently, Unbound with "qname-minimisation: yes" falls back to the full QNAME when it receives a NXDOMAIN. This is to work around broken name servers such as Akamai's. It defeats the point of QNAME minimisation (privacy).
It would be nice if the "qname-minimistaion:" parameter were tri-valued: yes, no and "strict". The new value "strict" would mean "be picky, apply the DNS rules stricly, do not fallback when you received a NXDOMAIN".
I added a qname-minimisation-strict configuration option. When enabled Unbound will not fall-back to the full QNAME. This option only has effect when qname-minimisation is enabled.
Also note that, even without the strict option, Unbound will not fall-back when receiving an NXDOMAIN rcode for a DNSSEC signed zone.
Thanks! Testing soon.