alanpae at
Sun Apr 8 20:24:47 CEST 2012

> Alan,
> > What I want is from my resolver to use DNSSEC.
> > 
> > So it looks like I need to recompile everything with unbounds
> > library and probably not use ISC's BIND resolver library.  Is that
> > correct?
> No, not at all. What you have to do is get your resolver to speak to
> your newly setup Unbound, by adding it's address to /etc/resolv.conf on
> the client machines that should use it.

If that's all I need to do then I'm all setup.

Many thanks,

> That looks ok, as long as dig is actually using your Unbound. Best to
> force it to query that explicitly by specifying the IP of your Unbound
>         dig @ +dnssec .

> As mentioned above, point your /etc/resolv.conf to Unbound.

Did that.  Same results so it likes like I'm all set.