RPZ: is this config correct?
George Thessalonikefs
george at nlnetlabs.nl
Fri Jul 16 12:47:04 UTC 2021
Hi Andreas,
Thanks for pointing out!
We have now introduced (on master branch) 'http-user-agent:' and
'hide-http-user-agent:' as new options to better control the User-Agent
HTTP header.
Best regards,
-- George
On 22/05/2021 00:13, A. Schulze via Unbound-users wrote:
> One side note on disclosing unbound version:
>
> My own webserver's log
>> 2001:db8::53 - - [22/May/2021:00:00:21 +0200] "GET /downloads/rpz HTTP/1.1" 200 210627 "-" "unbound/1.13.2"
>
> The real unbound version is used as http user agent header. This version is disclosed even if
> I set 'hide-version: yes' or obfuscate 'version: "foobar/42"'
>
> Maybe the user-agent header could be somehow synchronized with the mentioned settings.
>
> Andreas
>
More information about the Unbound-users
mailing list