On 12.06.2015 16:58, Paul Wouters wrote: > On Fri, 12 Jun 2015, Matthew Miller wrote: > >> Another integration concern: the network config GUI (and ifcfg files, >> for that matter) let me list specific DNS servers. With this >> feature, are those used (and if so, how)? If not, is my configuration >> just silently ignored? > > I do not know if it is supported currently, but support for that is > very trivial. If unbound is found running, issue: > > unbound-control forward_add . 1.2.3.4 5.6.7.8 > > I'm not sure whose job that would be. > > Paul This should be ideally left to the network configuration software (e.g. NM). Dnssec-trigger will not touch any forward zones that are already configured in Unbound and it didn't configured them itself. While technically this should not be a problem, and everything should work properly (since forward zones are configured properly), this should be ideally done only by the dnssec-trigger based on the information passed by VPN to the NM. Tomas -- Tomas Hozza Software Engineer - EMEA ENG Developer Experience PGP: 1D9F3C2D Red Hat Inc. http://cz.redhat.com -- devel mailing list devel@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/devel Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct