nixpkgs/nixos/modules
Raito Bezarius 4f461f7b77 nixos/modules/system/resolved: disable DNSSEC validation by default
Historically, we allowed downgrade of DNSSEC, but some folks argue
this may decrease actually the security posture to do opportunistic DNSSEC.

In addition, the current implementation of (opportunistic) DNSSEC validation
is broken against "in the wild" servers which are usually slightly non-compliant.

systemd upstream recommended to me (in personal communication surrounding
the All Systems Go 2023 conference) to disable DNSSEC validation until
they work on it in a significant capacity, ideally, by next year.
2023-09-13 11:49:16 +02:00
..
config Merge pull request #254149 from nbraud/noto-emoji 2023-09-12 16:27:58 +02:00
hardware nvidia,nixos/nvidia: add datacenter drivers compatible with default cudaPkgs 2023-09-12 07:17:33 +02:00
i18n/input-method uim: remove qt4, fix qt5 2023-09-04 13:54:50 +02:00
image modules/image/repart: Fix stripNixStorePrefix 2023-08-22 13:09:03 +02:00
installer nixos/iso-image: Remove leftover false dichotomy between console/serial 2023-09-06 14:10:09 -04:00
misc nixos/doc: Improve documentation of documentation 2023-08-12 22:28:04 +03:00
profiles nixos/installation-device: allow nix-copy for root/nixos user 2023-08-07 16:48:49 +02:00
programs nixos/yazi: add to module-list.nix 2023-09-13 14:48:24 +08:00
security nixos/acme: rename option credentialsFile to environmentFile 2023-09-11 16:34:20 +00:00
services Merge pull request #252283 from flokli/fcc-unlock-extra 2023-09-13 10:18:06 +02:00
system nixos/modules/system/resolved: disable DNSSEC validation by default 2023-09-13 11:49:16 +02:00
tasks Merge pull request #254429 from ctheune/fix-swraid-for-old-init 2023-09-11 09:11:10 +03:00
testing Merge pull request #219106 from m-bdf/nixos-testing-increase-device-timeout 2023-06-20 11:48:45 +02:00
virtualisation Merge pull request #253146 from rnhmjoj/pr-anbox 2023-09-05 23:46:54 +02:00
module-list.nix nixos/yazi: add to module-list.nix 2023-09-13 14:48:24 +08:00
rename.nix nixos/dhcp(46): remove 2023-07-28 16:35:40 +02:00