<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">
</head>
<body text="#000000" bgcolor="#FFFFFF">
unbound is having issues with a particular domain and
powerdns_recursor and bind both work fine.
<br>
<br>
Trying to lookup "bluebirdrvpark.ca".
<br>
<br>
The authoritative hosts are "ns1.editnew.net" and "ns2.editnew.net".
<br>
<br>
Unbound does not seem to like the answers it is getting from either
of these name servers.
<br>
I'm not in control or contact with them.
<br>
<br>
I've tried unbound 1.4.21 on CentOS 6.5 and
<br>
unbound 1.4.22 on Ubuntu 14.04
<br>
<br>
dig @127.0.0.1 ns2.editnew.net
<br>
<br>
Jun 10 08:44:41 media2 unbound: [9321:0] info: start of service
(unbound 1.4.22).
<br>
Jun 10 08:44:41 media2 unbound: [9321:1] info: 127.0.0.1 local. SOA
IN
<br>
Jun 10 08:44:41 media2 unbound: [9321:1] info: resolving local. SOA
IN
<br>
Jun 10 08:44:41 media2 unbound: [9321:1] info: priming . IN NS
<br>
Jun 10 08:44:42 media2 unbound: [9321:1] info: response for . NS IN
<br>
Jun 10 08:44:42 media2 unbound: [9321:1] info: reply from <.>
192.5.5.241#53
<br>
Jun 10 08:44:42 media2 unbound: [9321:1] info: query response was
ANSWER
<br>
Jun 10 08:44:42 media2 unbound: [9321:1] info: priming successful
for . NS IN
<br>
Jun 10 08:44:42 media2 unbound: [9321:1] info: response for local.
SOA IN
<br>
Jun 10 08:44:42 media2 unbound: [9321:1] info: reply from <.>
193.0.14.129#53
<br>
Jun 10 08:44:42 media2 unbound: [9321:1] info: query response was
NXDOMAIN ANSWER
<br>
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: 127.0.0.1
ns2.editnew.net. A IN
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: resolving
ns2.editnew.net. A IN
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: response for
ns2.editnew.net. A IN
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: reply from <.>
192.5.5.241#53
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: query response was
REFERRAL
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: resolving net. DNSKEY
IN
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: response for net.
DNSKEY IN
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: reply from
<net.> 192.35.51.30#53
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: query response was
ANSWER
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: response for
ns2.editnew.net. A IN
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: reply from
<net.> 192.54.112.30#53
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: query response was
REFERRAL
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: resolving
ns2.editnew.net. A IN
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: resolving
ns1.editnew.net. A IN
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: response for
ns2.editnew.net. A IN
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: reply from
<net.> 192.43.172.30#53
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: query response was
REFERRAL
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: response for
ns1.editnew.net. A IN
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: reply from
<net.> 192.42.93.30#53
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: query response was
REFERRAL
<br>
Jun 10 08:44:52 media2 unbound: [9321:0] info: resolving
ns1.editnew.net. A IN
<br>
Jun 10 08:44:53 media2 unbound: [9321:0] info: response for
ns1.editnew.net. A IN
<br>
Jun 10 08:44:53 media2 unbound: [9321:0] info: reply from
<net.> 192.31.80.30#53
<br>
Jun 10 08:44:53 media2 unbound: [9321:0] info: query response was
REFERRAL
<br>
Jun 10 08:44:53 media2 unbound: [9321:0] info: resolving
ns2.editnew.net. A IN
<br>
Jun 10 08:44:53 media2 unbound: [9321:0] info: response for
ns2.editnew.net. A IN
<br>
Jun 10 08:44:53 media2 unbound: [9321:0] info: reply from
<net.> 192.33.14.30#53
<br>
Jun 10 08:44:53 media2 unbound: [9321:0] info: query response was
REFERRAL
<br>
<br>
cat /etc/unbound/unbound.conf
<br>
<br>
server:
<br>
verbosity: 2
<br>
statistics-interval: 86400
<br>
statistics-cumulative: yes
<br>
extended-statistics: yes
<br>
num-threads: 2
<br>
interface: 0.0.0.0
<br>
interface: ::0
<br>
interface-automatic: yes
<br>
port: 53
<br>
outgoing-range: 4096
<br>
outgoing-port-permit: 32768-65535
<br>
outgoing-port-avoid: 0-32767
<br>
outgoing-num-tcp: 10
<br>
incoming-num-tcp: 10
<br>
so-rcvbuf: 8m
<br>
max-udp-size: 3072
<br>
msg-cache-size: 64m
<br>
msg-cache-slabs: 4
<br>
rrset-cache-size: 128m
<br>
rrset-cache-slabs: 4
<br>
infra-cache-slabs: 4
<br>
do-ip4: yes
<br>
do-ip6: no
<br>
do-udp: yes
<br>
do-tcp: yes
<br>
do-daemonize: yes
<br>
access-control: 0.0.0.0/0 deny
<br>
access-control: 127.0.0.0/8 allow
<br>
access-control: 10.0.0.0/8 allow
<br>
access-control: 192.168.0.0/16 allow
<br>
access-control: 172.16.0.0/12 allow
<br>
chroot: ""
<br>
username: "unbound"
<br>
directory: "/etc/unbound"
<br>
use-syslog: yes
<br>
log-time-ascii: yes
<br>
log-queries: yes
<br>
pidfile: "/var/run/unbound.pid"
<br>
root-hints: "root.hints"
<br>
hide-identity: yes
<br>
hide-version: yes
<br>
harden-glue: no
<br>
harden-dnssec-stripped: no
<br>
harden-below-nxdomain: no
<br>
harden-referral-path: no
<br>
use-caps-for-id: no
<br>
private-address: 10.0.0.0/8
<br>
private-address: 172.16.0.0/12
<br>
private-address: 192.168.0.0/16
<br>
private-address: fd00::/8
<br>
private-address: fe80::/10
<br>
unwanted-reply-threshold: 10000000
<br>
do-not-query-address: 127.0.0.1/8
<br>
do-not-query-address: ::1
<br>
do-not-query-localhost: yes
<br>
prefetch: yes
<br>
prefetch-key: yes
<br>
rrset-roundrobin: yes
<br>
minimal-responses: yes
<br>
# dlv-anchor-file: "/etc/unbound/dlv.isc.org.key"
<br>
# trusted-keys-file: <i class="moz-txt-slash"><span
class="moz-txt-tag">/</span>etc/unbound/keys.d<span
class="moz-txt-tag">/</span></i>*.key
<br>
# auto-trust-anchor-file: "/var/lib/unbound/root.anchor"
<br>
val-clean-additional: yes
<br>
val-permissive-mode: yes
<br>
val-log-level: 2
<br>
key-cache-slabs: 4
<br>
<br>
remote-control:
<br>
control-enable: yes
<br>
control-interface: 127.0.0.1
<br>
control-port: 953
<br>
server-key-file: "/etc/unbound/unbound_server.key"
<br>
server-cert-file: "/etc/unbound/unbound_server.pem"
<br>
control-key-file: "/etc/unbound/unbound_control.key"
<br>
control-cert-file: "/etc/unbound/unbound_control.pem"
<br>
<br>
</body>
</html>