DNSSEC requires the system time to be synced in order to work, as the signature date and expiration need to be checked by resolvers. But it is possible that syncing the times requires doing DNS queries. Add a paragraph to the FAQ explaining how to break this cycle by asking nss-resolved to always avoid DNSSEC when chronyd tries to resolve hostnames. |
||
---|---|---|
.. | ||
chrony.conf.adoc | ||
chronyc.adoc | ||
chronyd.adoc | ||
contributing.adoc | ||
faq.adoc | ||
installation.adoc | ||
Makefile.in |