diff -up dnscrypt-proxy-2.0.14/dnscrypt-proxy/example-dnscrypt-proxy.toml.custom_config dnscrypt-proxy-2.0.14/dnscrypt-proxy/example-dnscrypt-proxy.toml --- dnscrypt-proxy-2.0.14/dnscrypt-proxy/example-dnscrypt-proxy.toml.custom_config 2018-04-27 01:14:14.000000000 +0200 +++ dnscrypt-proxy-2.0.14/dnscrypt-proxy/example-dnscrypt-proxy.toml 2018-05-06 02:19:56.176052976 +0200 @@ -33,7 +33,7 @@ ## List of local addresses and ports to listen to. Can be IPv4 and/or IPv6. ## Note: When using systemd socket activation, choose an empty set (i.e. [] ). -listen_addresses = ['127.0.0.1:53', '[::1]:53'] +listen_addresses = [] ## Maximum number of simultaneous client connections to accept @@ -99,12 +99,12 @@ keepalive = 30 ## log file for the application -# log_file = 'dnscrypt-proxy.log' +# log_file = '/var/log/dnscrypt-proxy/dnscrypt-proxy.log' ## Use the system logger (syslog on Unix, Event Log on Windows) -# use_syslog = true +use_syslog = true ## Delay, in minutes, after which certificates are reloaded @@ -197,7 +197,7 @@ block_ipv6 = false ## example.com 9.9.9.9 ## example.net 9.9.9.9,8.8.8.8,1.1.1.1 -# forwarding_rules = 'forwarding-rules.txt' +# forwarding_rules = '/etc/dnscrypt-proxy/forwarding-rules.txt' @@ -213,7 +213,7 @@ block_ipv6 = false ## example.com 10.1.1.1 ## www.google.com forcesafesearch.google.com -# cloaking_rules = 'cloaking-rules.txt' +# cloaking_rules = '/etc/dnscrypt-proxy/cloaking-rules.txt' @@ -262,7 +262,7 @@ cache_neg_max_ttl = 600 ## Path to the query log file (absolute, or relative to the same directory as the executable file) - # file = 'query.log' + # file = '/var/log/dnscrypt-proxy/query.log' ## Query log format (currently supported: tsv and ltsv) @@ -288,7 +288,7 @@ cache_neg_max_ttl = 600 ## Path to the query log file (absolute, or relative to the same directory as the executable file) - # file = 'nx.log' + # file = '/var/log/dnscrypt-proxy/nx.log' ## Query log format (currently supported: tsv and ltsv) @@ -318,12 +318,12 @@ cache_neg_max_ttl = 600 ## Path to the file of blocking rules (absolute, or relative to the same directory as the executable file) - # blacklist_file = 'blacklist.txt' + # blacklist_file = '/etc/dnscrypt-proxy/blacklist.txt' ## Optional path to a file logging blocked queries - # log_file = 'blocked.log' + # log_file = '/var/log/dnscrypt-proxy/blocked.log' ## Optional log format: tsv or ltsv (default: tsv) @@ -346,12 +346,12 @@ cache_neg_max_ttl = 600 ## Path to the file of blocking rules (absolute, or relative to the same directory as the executable file) - # blacklist_file = 'ip-blacklist.txt' + # blacklist_file = '/etc/dnscrypt-proxy/ip-blacklist.txt' ## Optional path to a file logging blocked queries - # log_file = 'ip-blocked.log' + # log_file = '/var/log/dnscrypt-proxy/ip-blocked.log' ## Optional log format: tsv or ltsv (default: tsv) @@ -374,12 +374,12 @@ cache_neg_max_ttl = 600 ## Path to the file of whitelisting rules (absolute, or relative to the same directory as the executable file) - # whitelist_file = 'whitelist.txt' + # whitelist_file = '/etc/dnscrypt-proxy/whitelist.txt' ## Optional path to a file logging whitelisted queries - # log_file = 'whitelisted.log' + # log_file = '/var/log/dnscrypt-proxy/whitelisted.log' ## Optional log format: tsv or ltsv (default: tsv) @@ -449,7 +449,7 @@ cache_neg_max_ttl = 600 [sources.'public-resolvers'] urls = ['https://raw.githubusercontent.com/DNSCrypt/dnscrypt-resolvers/master/v2/public-resolvers.md', 'https://download.dnscrypt.info/resolvers-list/v2/public-resolvers.md'] - cache_file = 'public-resolvers.md' + cache_file = '/var/cache/dnscrypt-proxy/public-resolvers.md' minisign_key = 'RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3' refresh_delay = 72 prefix = '' @@ -459,7 +459,7 @@ cache_neg_max_ttl = 600 # [sources.'parental-control'] # urls = ['https://raw.githubusercontent.com/DNSCrypt/dnscrypt-resolvers/master/v2/parental-control.md', 'https://download.dnscrypt.info/resolvers-list/v2/parental-control.md'] - # cache_file = 'parental-control.md' + # cache_file = '/var/cache/dnscrypt-proxy/parental-control.md' # minisign_key = 'RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3'