resolved: lower SERVFAIL cache timeout from 30s to 10s
authorLennart Poettering <lennart@poettering.net>
Thu, 12 Nov 2020 16:52:09 +0000 (17:52 +0100)
committerZbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl>
Tue, 8 Dec 2020 17:08:31 +0000 (18:08 +0100)
commit9e5bf68702a0d39eebd40e55fc2bdf847b0c49c7
treed3bb9c84020ecb7220caca41e5efb6471a28af78
parent98571eb99cc08fb1a44a8bbeac4aa6faea2107e7
resolved: lower SERVFAIL cache timeout from 30s to 10s

Apparently 30s is a bit too long for some cases, see #5552. But not
caching SERVFAIL at all also breaks stuff, see explanation in
201d99584ed7af8078bb243ce2587e5455074713.

Let's try to find some middle ground, by lowering the cache timeout to
10s. This should be ample for the problem
201d99584ed7af8078bb243ce2587e5455074713 attackes, but not as long as
half a miute, as #5552 complains.

Fixes: #5552
(cherry picked from commit 19bcef9dc3fde342f138394333ab04d7e44b7da2)
src/resolve/resolved-dns-cache.c