On 08/03/2022 16.23, Matthew Richardson wrote:
Running 5.4.4, adding an NTA seems very
straightforward:-
[...]
What is the precise incantation to remove it when it is no longer required?
The following do not work:
The .set_insecure function *replaces* the NTA set. And naturally, the
question only matters if you're doing dynamic reconfiguration. Usually
people just restart the service to get new config, I assume. Anything
unclear in the docs?
https://knot-resolver.readthedocs.io/en/stable/config-dnssec.html#trust_anc…
Also, does Knot Resolver allow an automatic timeout
when setting NTAs as
Bind does?
No, currently it doesn't.
--Vladimir