Skip to content

Commit

Permalink
- Fix NLnetLabs#1128: Cannot override tcp-upstream and tls-upstream with
Browse files Browse the repository at this point in the history
  forward-tcp-upstream and forward-tls-upstream.
  • Loading branch information
wcawijngaards committed Oct 8, 2024
1 parent e671716 commit dcf7afd
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 0 deletions.
2 changes: 2 additions & 0 deletions doc/Changelog
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
8 October 2024: Wouter
- Fix #1149: unbound-control-setup hangs sometimes depending on
the openssl version.
- Fix #1128: Cannot override tcp-upstream and tls-upstream with
forward-tcp-upstream and forward-tls-upstream.

3 October 2024: Yorgos
- Fix CVE-2024-8508, unbounded name compression could lead to denial
Expand Down
3 changes: 3 additions & 0 deletions doc/unbound.conf.5.in
Original file line number Diff line number Diff line change
Expand Up @@ -566,6 +566,9 @@ tls\-system\-cert to load CA certs, otherwise the connections cannot be
authenticated. This option enables TLS for all of them, but if you do not set
this you can configure TLS specifically for some forward zones with
forward\-tls\-upstream. And also with stub\-tls\-upstream.
If the tls\-upstream option is enabled, it is for all the forwards and stubs,
where the forward\-tls\-upstream and stub\-tls\-upstream options are ignored,
as if they had been set to yes.
.TP
.B ssl\-upstream: \fI<yes or no>
Alternate syntax for \fBtls\-upstream\fR. If both are present in the config
Expand Down

0 comments on commit dcf7afd

Please sign in to comment.