Comment 52 for bug 1211110

Revision history for this message
Robie Basak (racb) wrote :

Mathieu linked:

"""
* debian/patches/dns-manager-don-t-merge-split-DNS-search-domains.patch: do
    not add split DNS search domains to resolv.conf; doing so would risk
    leaking names to non-VPN DNS nameservers when attempting to resolve non-
    FQDN names. (LP: #1592721)
"""

You ask:

> I use split tunneling but I did not configure VPN to pass search domains along with the nameservers. Can't this be done automatically?

The answer to me appears to be "no", because then you risk leaking names to non-VPN DNS nameservers.