From f7f638e18f13ed6e45267880739f24e06e093943 Mon Sep 17 00:00:00 2001 From: "W.C.A. Wijngaards" Date: Mon, 9 Feb 2026 16:11:17 +0100 Subject: [PATCH] - Update generated man pages. --- doc/Changelog | 1 + doc/unbound.conf.5.in | 9 ++++++--- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/doc/Changelog b/doc/Changelog index fdfefb32a..0c7f35462 100644 --- a/doc/Changelog +++ b/doc/Changelog @@ -2,6 +2,7 @@ - Merge #1401: Add a new build-time option for system TLS. The --enable-system-tls flag enables the tls-use-system-policy-versions setting by default. + - Update generated man pages. 6 February 2026: Yorgos - Fix #1389: [FR] replacement with ECC-GOST12 according to RFC9558. diff --git a/doc/unbound.conf.5.in b/doc/unbound.conf.5.in index 55f86c17f..d24872d8e 100644 --- a/doc/unbound.conf.5.in +++ b/doc/unbound.conf.5.in @@ -1299,13 +1299,16 @@ Default: yes .INDENT 0.0 .TP .B tls\-use\-system\-policy\-versions: \fI\fP -Enable or disable general\-puspose version\-flexible TLS server configuration +Enable or disable general\-purpose version\-flexible TLS server configuration when serving TLS. This will allow the whole list of available TLS versions provided by the crypto library, which may have been further restricted by the system\(aqs crypto policy. .sp -By default Unbound only uses the latest available TLS version. +If disabled Unbound only uses the latest available TLS version. +.sp +The default depends on a compilation choice, it is set +at @SYSTEM_TLS_DEFAULT@ . .sp \fBCAUTION:\fP .INDENT 7.0 @@ -1321,7 +1324,7 @@ Changing the value requires a reload. .UNINDENT .UNINDENT .sp -Default: no +Default: @SYSTEM_TLS_DEFAULT@ .UNINDENT .INDENT 0.0 .TP