Klemens Nanni
Klemens Nanni
This allows for accepting clients based on their certificate authority: ``` x509-username-field issuer CN verify-x509-name ...CA=ExampleCA_ match-prefix ``` `tls-verify` or `plugin` can do the equivalent, but require additional code execution...
Modern clients make fancy requests, but passivedns only logs unsupported/unknown RR types under compile-time `DEBUG`, so they go unnoticed. Current [ldns](https://www.nlnetlabs.nl/projects/ldns/about/) 1.8.4 [already](https://github.com/NLnetLabs/ldns/commit/c8d888a73d5abbc063d95e2ca36c2578cd007355) [supports](https://github.com/NLnetLabs/ldns/commit/d34309fbe6a131215f2b7974a102aef28db3bf8f) [RFC 9460](https://www.rfc-editor.org/rfc/rfc9460.html) "Service Binding and Parameter...