On 11/12/19 9:16 AM, Stephane Bortzmeyer wrote:
Right, normal
policy rules only apply once before request starts.
So, same thing for RPZ?
Correct.
I'll think on the CNAME policies a bit more. There might be some
medium-term improvement - one that's not too hacky, before we get to
completely rewrite this API to some declarative style. Some additional
information has collected on this issue:
https://gitlab.labs.nic.cz/knot/knot-resolver/issues/217