From owner-freebsd-stable@freebsd.org Wed Jan 29 10:33:24 2020 Return-Path: Delivered-To: freebsd-stable@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 2EA531D3229 for ; Wed, 29 Jan 2020 10:33:24 +0000 (UTC) (envelope-from wolfgang@lyxys.ka.sub.org) Received: from saturn.lyxys.ka.sub.org (saturn.lyxys.ka.sub.org [217.29.35.151]) (using TLSv1 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4870FH04Kgz4QxC for ; Wed, 29 Jan 2020 10:33:22 +0000 (UTC) (envelope-from wolfgang@lyxys.ka.sub.org) Received: from saturn.lyxys.ka.sub.org (localhost [127.0.0.1]) by saturn.lyxys.ka.sub.org (8.15.2/8.15.2) with ESMTPS id 00TAVtap081304 (version=TLSv1 cipher=DHE-RSA-CAMELLIA256-SHA bits=256 verify=NO) for ; Wed, 29 Jan 2020 11:31:57 +0100 (CET) (envelope-from wolfgang@lyxys.ka.sub.org) Received: (from wolfgang@localhost) by saturn.lyxys.ka.sub.org (8.15.2/8.15.2/Submit) id 00TAVsMk081303; Wed, 29 Jan 2020 11:31:54 +0100 (CET) (envelope-from wolfgang) Date: Wed, 29 Jan 2020 11:31:54 +0100 (CET) Message-Id: <202001291031.00TAVsMk081303@saturn.lyxys.ka.sub.org> From: wolfgang@lyxys.ka.sub.org To: freebsd-stable@freebsd.org Subject: local_unbound: How to prevent caching of SERVFAIL? X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.4.3 (saturn.lyxys.ka.sub.org [127.0.0.1]); Wed, 29 Jan 2020 11:31:58 +0100 (CET) X-Rspamd-Queue-Id: 4870FH04Kgz4QxC X-Spamd-Bar: -- Authentication-Results: mx1.freebsd.org; dkim=none; dmarc=none; spf=pass (mx1.freebsd.org: domain of wolfgang@lyxys.ka.sub.org designates 217.29.35.151 as permitted sender) smtp.mailfrom=wolfgang@lyxys.ka.sub.org X-Spamd-Result: default: False [-2.67 / 15.00]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-0.999,0]; IP_SCORE(-1.37)[ip: (-5.47), ipnet: 217.29.32.0/20(-0.75), asn: 16188(-0.59), country: DE(-0.02)]; R_SPF_ALLOW(-0.20)[+mx]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MIME_GOOD(-0.10)[text/plain]; TO_DN_NONE(0.00)[]; PREVIOUSLY_DELIVERED(0.00)[freebsd-stable@freebsd.org]; RCPT_COUNT_ONE(0.00)[1]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; DMARC_NA(0.00)[sub.org]; FROM_NO_DN(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; R_DKIM_NA(0.00)[]; SUBJECT_ENDS_QUESTION(1.00)[]; ASN(0.00)[asn:16188, ipnet:217.29.32.0/20, country:DE]; MIME_TRACE(0.00)[0:+]; RCVD_TLS_ALL(0.00)[]; RCVD_COUNT_TWO(0.00)[2] X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 29 Jan 2020 10:33:24 -0000 Hi, using local_unbound on FreeBSD 11.3 I have the problem that an occasional SERVFAIL is cached for several minutes (not sure about the exact length of time but something like 5 to 15 minutes). Is it possible to reduce this to something like 10 seconds? I did set cache-max-negative-ttl but that apparently only sets the ttl for caching NXDOMAIN. Wolfgang