From 62fd6e2c7cf65d08f7cc7ff0cf2b5d170ccce27f Mon Sep 17 00:00:00 2001 From: strawberry Date: Mon, 29 Apr 2024 14:31:10 -0400 Subject: [PATCH] set AD bit to false in hickory this is purely DNSSEC related which we don't use, and DNSSEC on matrix is unbearable for federation (no one sets it up properly, it's extremely taxing, etc) Signed-off-by: strawberry --- src/service/globals/resolver.rs | 1 + 1 file changed, 1 insertion(+) diff --git a/src/service/globals/resolver.rs b/src/service/globals/resolver.rs index 9aa4d9ba..3d1acd5d 100644 --- a/src/service/globals/resolver.rs +++ b/src/service/globals/resolver.rs @@ -74,6 +74,7 @@ impl Resolver { 4 => hickory_resolver::config::LookupIpStrategy::Ipv6thenIpv4, _ => hickory_resolver::config::LookupIpStrategy::Ipv4thenIpv6, }; + opts.authentic_data = false; let resolver = Arc::new(TokioAsyncResolver::tokio(conf, opts)); let overrides = Arc::new(StdRwLock::new(TlsNameMap::new()));