diff --git a/doc/Changelog b/doc/Changelog index 1eebf3ea2..4f26ea58a 100644 --- a/doc/Changelog +++ b/doc/Changelog @@ -1,3 +1,7 @@ +23 May 2016: Ralph + - Fix #767: Reference to an expired Internet-Draft in + harden-below-nxdomain documentation. + 20 May 2016: Ralph - No QNAME minimisation fall-back for NXDOMAIN answers from DNSSEC signed zones. diff --git a/doc/unbound.conf.5.in b/doc/unbound.conf.5.in index ef06b36cb..9f5f00712 100644 --- a/doc/unbound.conf.5.in +++ b/doc/unbound.conf.5.in @@ -577,6 +577,7 @@ might return nxdomain for empty nonterminals (that usually happen for reverse IP address lookups), and thus may be incompatible with this. To try to avoid this only DNSSEC-secure nxdomains are used, because the old software does not have DNSSEC. Default is off. +Currently, draft\-ietf\-dnsop\-nxdomain\-cut promotes this technique. .TP .B harden\-referral\-path: \fI Harden the referral path by performing additional queries for