Maintained by: NLnet Labs

[Unbound-users] DNSSec validation

Nikos Mavrogiannopoulos
Wed Oct 3 11:19:52 CEST 2012


On Wed, Oct 3, 2012 at 10:58 AM, W.C.A. Wijngaards <wouter at nlnetlabs.nl> wrote:

> The trust anchor was working all along, just fine.
> The server at 10.0.2.3, is your DNS resolver, and it does not have
> DNSSEC enabled.  Use unbound without it: comment out the
> ub_ctx_resolvconf call.  Unbound then goes into full resolver mode.
> It is wasteful and you have no fast cache hits, but it'll work with
> DNSSEC.

Now it is perfectly ok, thank you!

> It would be better (especially for bigger sites or bigger usage) to
> upgrade the upstream cache.

I'll notify the administrators here.

regards,
Nikos