From df7e8ff3d767a06ef89bd66761a1b13727713bd9 Mon Sep 17 00:00:00 2001 From: strawberry Date: Mon, 29 Apr 2024 14:31:10 -0400 Subject: [PATCH] set AD bit to false in hickory this is purely DNSSEC related which we don't use, and DNSSEC on matrix is unbearable for federation (no one sets it up properly, it's extremely taxing, etc) Signed-off-by: strawberry --- src/service/globals/resolver.rs | 1 + 1 file changed, 1 insertion(+) diff --git a/src/service/globals/resolver.rs b/src/service/globals/resolver.rs index 9aa4d9ba..3d1acd5d 100644 --- a/src/service/globals/resolver.rs +++ b/src/service/globals/resolver.rs @@ -74,6 +74,7 @@ impl Resolver { 4 => hickory_resolver::config::LookupIpStrategy::Ipv6thenIpv4, _ => hickory_resolver::config::LookupIpStrategy::Ipv4thenIpv6, }; + opts.authentic_data = false; let resolver = Arc::new(TokioAsyncResolver::tokio(conf, opts)); let overrides = Arc::new(StdRwLock::new(TlsNameMap::new()));