F23 System Wide Change: Default Local DNS Resolver

David Howells dhowells at redhat.com
Tue Jun 2 14:58:24 UTC 2015


Jan Kurik <jkurik at redhat.com> wrote:

> Install a local DNS resolver trusted for the DNSSEC validation running on
> 127.0.0.1:53. This must be the only name server entry in /etc/resolv.conf.
>
> The automatic name server entries received via dhcp/vpn/wireless
> configurations should be stored separately (e.g. this is stored in the
> NetworkManager internal state), as transitory name servers to be used by the
> trusted local resolver. In all cases, DNSSEC validation will be done
> locally.

How does this interact with dnsmasq which also wants to be the only name
server entry in resolv.conf?

David


More information about the devel mailing list