Censorship

Jaap Akkerhuis jaap at NLnetLabs.nl
Wed Jul 22 10:08:02 UTC 2020


 Toni Mueller via Unbound-users writes:
 >
 > My local ISP, at least until very recently, always delivered doctored
 > answers, but taken from who-knows-where. I run my own authoritative name
 > servers, and when I tried to query them, I got stale answers with a
 > bogus, uniform TTL of 1 minute, everytime. I also wouldn't get any
 > updates until hours later. They also have a nanny filter which I can't
 > really disable.

Such a problem can of course not be fixed by unbound alone.

Have a look at <https://nlnetlabs.nl/projects/dnssec-trigger/about/>
for a one idea to deal with that. Another popular method is using
"Stubby" (See <https://getdnsapi.net/> where some solutions are
mentioned.

	jaap


More information about the Unbound-users mailing list