summaryrefslogtreecommitdiffstats
path: root/doc/config-dnssec.rst
blob: f20e2b30c42bee7f370f38aca8bb5a8b178800fe (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
.. SPDX-License-Identifier: GPL-3.0-or-later

.. _dnssec-config:

*************************
DNSSEC, data verification
*************************

Good news! Knot Resolver uses secure configuration by default, and this configuration
should not be changed unless absolutely necessary, so feel free to skip over this section.

.. include:: ../daemon/lua/trust_anchors.rst

DNSSEC is main technology to protect data, but it is also possible to change how strictly
resolver checks data from insecure DNS zones:

.. include:: ../lib/layer/mode.rst