root@OPNsense:/usr/local/etc/stubby # cat /usr/local/etc/stubby/stubby.ymlresolution_type: GETDNS_RESOLUTION_STUBdns_transport_list: - GETDNS_TRANSPORT_TLStls_authentication: GETDNS_AUTHENTICATION_REQUIREDtls_query_padding_blocksize: 128edns_client_subnet_private : 1round_robin_upstreams: 0idle_timeout: 10000tls_ca_path: "/etc/ssl/"tls_cipher_list: "EECDH+AESGCM:EECDH+CHACHA20"tls_ciphersuites: "TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256"tls_min_version: GETDNS_TLS1_2tls_max_version: GETDNS_TLS1_3listen_addresses: - 127.0.0.1@8053# - 0::1@8053dnssec: GETDNS_EXTENSION_TRUEappdata_dir: "/var/cache/stubby"tls_ca_file: "/usr/local/share/certs/ca-root-nss.crt"upstream_recursive_servers: - address_data: 9.9.9.9 tls_auth_name: "dns.quad9.net" tls_port: 853 - address_data: 1.1.1.1 tls_auth_name: "cloudflare-dns.com" tls_port: 853
do-not-query-localhost: noforward-zone:name: "."forward-addr: 192.168.5.160@8053
resolution_type: GETDNS_RESOLUTION_STUBdns_transport_list: - GETDNS_TRANSPORT_TLStls_authentication: GETDNS_AUTHENTICATION_REQUIREDdnssec_return_status: GETDNS_EXTENSION_TRUEtls_query_padding_blocksize: 128edns_client_subnet_private : 1round_robin_upstreams: 1idle_timeout: 10000tls_ca_path: "/etc/ssl/"tls_cipher_list: "EECDH+AESGCM:EECDH+CHACHA20"tls_ciphersuites: "TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256"tls_min_version: GETDNS_TLS1_2tls_max_version: GETDNS_TLS1_3listen_addresses: - 127.0.0.1@8053# - 0::1@8053#dnssec: GETDNS_EXTENSION_TRUEappdata_dir: "/var/cache/stubby"#dnssec_trust_anchors: "/usr/local/sbin/unbound-anchor"dnssec_trust_anchors: - "/usr/local/etc/unbound/root.key"tls_ca_file: "/usr/local/share/certs/ca-root-nss.crt"upstream_recursive_servers:## Quad 9 'secure' service - Filters, does DNSSEC, doesn't send ECS - address_data: 9.9.9.9 tls_auth_name: "dns.quad9.net" tls_port: 853## Cloudflare 1.1.1.1 and 1.0.0.1 - address_data: 1.1.1.1 tls_auth_name: "cloudflare-dns.com" tls_port: 853
server:do-not-query-localhost: noforward-zone:name: "."forward-addr: 127.0.0.1@8053