Maintained by: NLnet Labs

[Unbound-users] Best way to be notified of DNSSEC validation failures?

Augie Schwer
Wed Mar 7 21:41:08 CET 2012


What is the best way to be notified of DNSSEC validation failures in Unbound?

If I set "verbosity" to "2" I receive a log entry of :

"Could not establish a chain of trust to keys for <dnssec-failed.org.
DNSKEY IN>"

When testing a failed host -- I could use this to be notified of
validation failures on specific domains.

Is there a better way?


-- 
Augie Schwer    -    Augie at Schwer.us    -    http://schwer.us