diff --git a/GCP-Debian-11.sh b/GCP-Debian-11.sh index c6929fe..9728cb1 100644 --- a/GCP-Debian-11.sh +++ b/GCP-Debian-11.sh @@ -18,6 +18,7 @@ sudo ufw allow 22/tcp sudo tuned-adm profile virtual-guest echo 'server: + trust-anchor-file: "/var/lib/unbound/root.key trust-anchor-signaling: yes root-key-sentinel: yes tls-cert-bundle: /etc/ssl/certs/ca-certificates.crt @@ -50,6 +51,8 @@ forward-zone: forward-addr: 2606:4700:4700::1112@853#security.cloudflare-dns.com forward-addr: 2606:4700:4700::1002@853#security.cloudflare-dns.com' | sudo tee /etc/unbound/unbound.conf.d/custom.conf +sudo mv /etc/unbound/unbound.conf.d/root-auto-trust-anchor-file.conf /etc/unbound/unbound.conf.d/root-auto-trust-anchor-file.conf.bk + mkdir -p /etc/systemd/system/unbound.service.d echo $'[Service] CapabilityBoundingSet=CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_SYS_RESOURCE CAP_NET_RAW