dnssec: enable

This commit is contained in:
Rouven Seifert 2023-09-24 22:46:12 +02:00
parent 02f281a4ec
commit e7cb531d8b
Signed by: rouven.seifert
GPG key ID: B95E8FE6B11C4D09
3 changed files with 4 additions and 0 deletions

View file

@ -14,6 +14,7 @@
useNetworkd = true; useNetworkd = true;
enableIPv6 = true; enableIPv6 = true;
}; };
services.resolved.dnssec = "true";
systemd.network = { systemd.network = {
enable = true; enable = true;
networks."10-loopback" = { networks."10-loopback" = {

View file

@ -8,6 +8,7 @@
}; };
services.resolved = { services.resolved = {
enable = true; enable = true;
dnssec = "yes";
# make room for the adguard dns # make room for the adguard dns
extraConfig = '' extraConfig = ''
[Resolve] [Resolve]

View file

@ -11,6 +11,8 @@
owner = config.users.users.systemd-network.name; owner = config.users.users.systemd-network.name;
}; };
}; };
# allow downgrade since fritzbox at home doesn't support it (yet?)
services.resolved.dnssec = "allow-downgrade";
networking = { networking = {
useNetworkd = true; useNetworkd = true;
hostName = "thinkpad"; hostName = "thinkpad";