c542f805ddc3ae28007c15827ef2e8a8247452bc |
|
29-Jan-2016 |
Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> |
man: reword sentence |
dbc7bede4a96d9a4d2fa75b6fb2a51076756b051 |
|
29-Jan-2016 |
Lennart Poettering <lennart@poettering.net> |
man: actually say which section resolv.conf's setting should be placed in |
adc800a6e0bf5483585e4210cf7125a7477ad85e |
|
26-Jan-2016 |
Lennart Poettering <lennart@poettering.net> |
resolved: allow configuration of routing domains in Domains= |
524f3e5c9d1eb2fba3d0b65d1790018163ba0b20 |
|
26-Jan-2016 |
Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> |
man: fix references to a few external man pages
Noticed in pull request #2067. |
60402bdc52a7569f9f6fd00486e34796c4f6f55d |
|
19-Jan-2016 |
Daniel Mack <daniel@zonque.org> |
resolved: remove configuration knobs for mDNS until it's ready
These bits were intenionally left out while mDNS is under development.
Remove the exposed knobs and man page entries again until this is settled. |
d33b6cf343f5a1e073c3060878d2cc5fed54d150 |
|
05-Jan-2016 |
Lennart Poettering <lennart@poettering.net> |
resolved: try to detect fritz.box-style private DNS zones, and downgrade to non-DNSSEC mode for them
This adds logic to detect cases like the Fritz!Box routers which serve
a private DNS domain "fritz.box" under the TLD "box" that does not
exist in the root servers. If this is detected DNSSEC validation is
turned off for this private domain, thus improving compatibility with
such private DNS zones.
This should be fairly secure as we first rely on the proof that .box
does not exist before this logic is applied. Nevertheless the logic is
only enabled for DNSSEC=allow-downgrade mode.
This logic does not work for routers that set up a full DNS zone directly
under a non-existing TLD, as in that case we cannot prove
that the domain is truly non-existing according to the root servers. |
ad6c04756115809d615dede330213d73edf732a8 |
|
05-Jan-2016 |
Lennart Poettering <lennart@poettering.net> |
resolved,networkd: add a per-interface DNSSEC setting
This adds a DNSSEC= setting to .network files, and makes resolved honour
them. |
1ed8c0fbb4cc51413f3a6025233f41c19f154bc1 |
|
05-Jan-2016 |
Lennart Poettering <lennart@poettering.net> |
resolved: rename "downgrade-ok" mode to "allow-downgrade"
After discussing this with Tom, we figured out "allow-downgrade" sounds
nicer. |
b83d91c02947585df06207c604534d25d87b611f |
|
05-Jan-2016 |
Lennart Poettering <lennart@poettering.net> |
resolved: make MulticastDNS support configurable in resolved.conf
The option is already there, but wasn't exported in the configuration
file so far. Fix that. |
d57d3973a739fa7aa4c2e6c241588ba92f60e8d3 |
|
05-Jan-2016 |
Lennart Poettering <lennart@poettering.net> |
man: fix a few typos |
b5a8703fdb8e16f760bfb730df64f07173bb881d |
|
05-Jan-2016 |
Lennart Poettering <lennart@poettering.net> |
man: add documentation for dnssec-trust-anchors.d(5) |
519d39deeeec7121649f28e7287b7790e50d2979 |
|
05-Jan-2016 |
Lennart Poettering <lennart@poettering.net> |
man: add basic documentation for resolved.conf's DNSSEC= switch |
a51c10485af349eb15faa4d1a63b9818bcf3e589 |
|
25-Nov-2015 |
Lennart Poettering <lennart@poettering.net> |
resolved: add a generic DnsSearchDomain concept
With this change, we add a new object to resolved, "DnsSearchDomain="
which wraps a search domain. This is then used to introduce a global
search domain list, in addition to the existing per-link search domain
list which is reword to make use of this new object too.
This is preparation for implement proper unicast DNS search domain
support. |
9f2912db7887d82f95183d51f4af4db99454f6f4 |
|
25-Nov-2015 |
Lennart Poettering <lennart@poettering.net> |
man: fix documentation how /etc/resolv.conf is read
/etc/resolv.conf is only read when the DNS= setting does not appear at
all in resolved.conf, regardless if set to the empty list or anything
else. Correct that in the man page. |
a8eaaee72a2f06e0fb64fb71de3b71ecba31dafb |
|
06-Nov-2015 |
Jan Engelhardt <jengelh@inai.de> |
doc: correct orthography, word forms and missing/extraneous words |
b938cb902c3b5bca807a94b277672c64d6767886 |
|
06-Nov-2015 |
Jan Engelhardt <jengelh@inai.de> |
doc: correct punctuation and improve typography in documentation |
12b42c76672a66c2d4ea7212c14f8f1b5a62b78d |
|
18-Jun-2015 |
Tom Gundersen <teg@jklm.no> |
man: revert dynamic paths for split-usr setups
This did not really work out as we had hoped. Trying to do this upstream
introduced several problems that probably makes it better suited as a
downstream patch after all. At any rate, it is not releaseable in the
current state, so we at least need to revert this before the release.
* by adjusting the path to binaries, but not do the same thing to the
search path we end up with inconsistent man-pages. Adjusting the search
path too would be quite messy, and it is not at all obvious that this is
worth the effort, but at any rate it would have to be done before we
could ship this.
* this means that distributed man-pages does not make sense as they depend
on config options, and for better or worse we are still distributing
man pages, so that is something that definitely needs sorting out before
we could ship with this patch.
* we have long held that split-usr is only minimally supported in order
to boot, and something we hope will eventually go away. So before we start
adding even more magic/effort in order to make this work nicely, we should
probably question if it makes sense at all. |
681eb9cf2b831293a4f3d4c48a748d2e4a25d69e |
|
28-May-2015 |
Filipe Brandenburger <filbranden@google.com> |
man: generate configured paths in manpages
In particular, use /lib/systemd instead of /usr/lib/systemd in distributions
like Debian which still have not adopted a /usr merge setup.
Use XML entities from man/custom-entities.ent to replace configured paths while
doing XSLT processing of the original XML files. There was precedent of some
files (such as systemd.generator.xml) which were already using this approach.
This addresses most of the (manual) fixes from this patch:
http://anonscm.debian.org/cgit/pkg-systemd/systemd.git/tree/debian/patches/Fix-paths-in-man-pages.patch?h=experimental-220
The idea of using generic XML entities was presented here:
http://lists.freedesktop.org/archives/systemd-devel/2015-May/032240.html
This patch solves almost all the issues, with the exception of:
- Path to /bin/mount and /bin/umount.
- Generic statements about preference of /lib over /etc.
These will be handled separately by follow up patches.
Tested:
- With default configure settings, ran "make install" to two separate
directories and compared the output to confirm they matched exactly.
- Used a set of configure flags including $CONFFLAGS from Debian:
http://anonscm.debian.org/cgit/pkg-systemd/systemd.git/tree/debian/rules
Installed the tree and confirmed the paths use /lib/systemd instead of
/usr/lib/systemd and that no other unexpected differences exist.
- Confirmed that `make distcheck` still passes. |
e93549ef29c4123d9ee45acb5815048390201e49 |
|
04-Mar-2015 |
Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> |
Do not advertise .d snippets over main config file
For daemons which have a main configuration file, there's
little reason for the administrator to use configuration snippets.
They are useful for packagers which need to override settings, but
we shouldn't advertise that as the main way of configuring those
services.
https://bugs.freedesktop.org/show_bug.cgi?id=89397 |
b975b0d514321f169b3c4599a8ea92e13741b4e4 |
|
11-Feb-2015 |
Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> |
man: boilerplate unification |
798d3a524ea57aaf40cb53858aaa45ec702f012d |
|
04-Feb-2015 |
Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> |
Reindent man pages to 2ch |
f2dacc96b25528ca1b0caca6364a69d656cf1569 |
|
29-Nov-2014 |
Josh Triplett <josh@joshtriplett.org> |
resolved: Support resolved.conf.d directories in the usual search paths |
31a339fd7f0e87376bade9ebd7ae32c58d34cf85 |
|
11-Aug-2014 |
Lennart Poettering <lennart@poettering.net> |
man: update resolved man pages a bit |
252f2b9e854dced09cf0968417d1868e5fa90a06 |
|
04-Aug-2014 |
Lennart Poettering <lennart@poettering.net> |
man: bring resolved.conf up-to-date |
091a364c802e34a58f3260c9cb5db9b75c62215c |
|
19-May-2014 |
Tom Gundersen <teg@jklm.no> |
resolved: add daemon to manage resolv.conf
Also remove the equivalent functionality from networkd. |