Maintained by: NLnet Labs

[Unbound-users] old unbound, DNSSEC verification broke today

SM
Thu Mar 7 07:46:53 CET 2013


Hi Phil,
At 18:12 06-03-2013, Phil Pennock wrote:
>Yesterday, ICANN sent out notification of the root KSK Ceremony 12,
>which took place on February 12th.  Might be a factor?

That announcement was about the ceremony materials.

>With the trust anchor turned on, I get:
>
>root at coal:/etc/unbound# unbound -dd
>Nov 27 08:22:20 unbound[2919:0] notice: init module 0: validator
>Nov 27 08:22:20 unbound[2919:0] notice: init module 1: iterator
>Nov 27 08:22:20 unbound[2919:0] info: start of service (unbound 1.4.5).
>Nov 27 08:22:30 unbound[2919:0] info: failed to prime trust anchor 
>-- DNSKEY rrset is not secure <. DNSKEY IN>
>Nov 27 08:22:30 unbound[2919:0] info: failed to prime trust anchor 
>-- DNSKEY rrset is not secure <. DNSKEY IN>
>Nov 27 08:22:30 unbound[2919:0] info: failed to prime trust anchor 
>-- DNSKEY rrset is not secure <. DNSKEY IN>

I noticed a similar problem with a previous version.  I didn't 
encounter the problem with version 1.4.19.

Regards,
-sm