Maintained by: NLnet Labs

[Unbound-users] SERVFAIL for an abbreviated TLD local zone

Jeroen Massar
Mon Dec 8 07:41:25 CET 2014


On 2014-12-07 20:52, martin f krafft wrote:
[..]
> I fI remove the auto-trust-anchor-file config directive, it works,
> so it seems this is DNSSEC-related (none of my zones are signed
> yet). Can someone enlighten me and help em understand what's going
> on?

As the root does not know your custom zone, that custom zone is not
properly signed and voila ;)

Maybe what you want to do is use the 'search domain' option to point it
to the non-local edition; or .... disable dnssec (possibly selectively)

Greets,
 Jeroen