<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p>Just an example from working Windows setup:</p>
    <p># Unbound configuration file on windows.<br>
      # See example.conf for more settings and syntax<br>
      <br>
      server:<br>
          # verbosity level 0-4 of logging<br>
          verbosity: 0<br>
      <br>
          # if you want to log to a file use<br>
          # logfile: "C:\unbound.log"<br>
      <br>
          # on Windows, this setting makes reports go into the
      Application log<br>
          # found in ControlPanels - System tasks - Logs <br>
          use-syslog: yes<br>
          log-time-ascii: yes<br>
          num-threads: 4<br>
          cache-max-ttl: 14400<br>
          cache-min-ttl: 900<br>
          cache-max-negative-ttl: 60<br>
          infra-host-ttl: 60<br>
      #    root-hints: "C:\Program Files\Unbound\named.root"<br>
          hide-identity: yes<br>
          hide-version: yes<br>
          hide-trustanchor: yes<br>
      <br>
          do-ip6: no<br>
      <br>
          tls-cert-bundle: "C:\Squid\etc\squid\ca-bundle.crt"<br>
          tls-win-cert: yes<br>
          tcp-upstream: yes<br>
      <br>
          harden-short-bufsize: yes<br>
          harden-large-queries: yes<br>
          harden-below-nxdomain: yes<br>
          harden-algo-downgrade: yes<br>
          # 1.5.7 feature. Yes recommended.<br>
          # From 1.7.2 yes is default<br>
          #qname-minimisation: yes<br>
          aggressive-nsec: yes<br>
      <br>
          # select from the fastest servers this many times out of 1000.
      0 means<br>
          # the fast server select is disabled. prefetches are not sped
      up.<br>
          # fast-server-permil: 0<br>
          fast-server-permil: 100<br>
          # the number of servers that will be used in the fast server
      selection.<br>
          # fast-server-num: 3<br>
          fast-server-num: 4<br>
      <br>
          unwanted-reply-threshold: 10000000<br>
          do-not-query-localhost: no<br>
          prefetch: yes<br>
          prefetch-key: yes<br>
          rrset-roundrobin: yes<br>
          minimal-responses: yes<br>
      <br>
          access-control: 0.0.0.0/0 refuse<br>
          access-control: 127.0.0.0/8 allow_snoop<br>
          access-control: ::0/0 refuse<br>
          access-control: ::1 allow<br>
          access-control: ::ffff:127.0.0.1 allow<br>
      <br>
          #include: "C:\Program Files\Unbound\unbound_local" <br>
          include: "C:\Program Files\Unbound\unbound_ad_servers" <br>
      <br>
      # Remote control config section. <br>
      remote-control:<br>
          # Enable remote control with unbound-control(8) here.<br>
          # set up the keys and certificates with unbound-control-setup.<br>
          control-enable: yes<br>
              control-use-cert: no<br>
      <br>
      forward-zone:<br>
        name: "."<br>
      #  forward-addr: 208.67.222.222@53<br>
      #  forward-addr: 208.67.220.220@53<br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:1.1.1.1@853#cloudflare-dns.com">1.1.1.1@853#cloudflare-dns.com</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:1.0.0.1@853#cloudflare-dns.com">1.0.0.1@853#cloudflare-dns.com</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:9.9.9.9@853#dns.quad9.net">9.9.9.9@853#dns.quad9.net</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:149.112.112.112@853#dns.quad9.net">149.112.112.112@853#dns.quad9.net</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:145.100.185.15@443#dnsovertls.sinodun.com">145.100.185.15@443#dnsovertls.sinodun.com</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:145.100.185.16@443#dnsovertls1.sinodun.com">145.100.185.16@443#dnsovertls1.sinodun.com</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:185.49.141.37@853#getdnsapi.net">185.49.141.37@853#getdnsapi.net</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:89.233.43.71@853#unicast.censurfridns.dk">89.233.43.71@853#unicast.censurfridns.dk</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:158.64.1.29@853#kaitain.restena.lu">158.64.1.29@853#kaitain.restena.lu</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:145.100.185.18@853#dnsovertls3.sinodun.com">145.100.185.18@853#dnsovertls3.sinodun.com</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:145.100.185.17@853#dnsovertls2.sinodun.com">145.100.185.17@853#dnsovertls2.sinodun.com</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:199.58.81.218@853#dns.cmrg.net">199.58.81.218@853#dns.cmrg.net</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:94.130.110.185@853#ns1.dnsprivacy.at">94.130.110.185@853#ns1.dnsprivacy.at</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:94.130.110.178@853#ns2.dnsprivacy.at">94.130.110.178@853#ns2.dnsprivacy.at</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:99.192.182.200@853#iana.tenta.io">99.192.182.200@853#iana.tenta.io</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:99.192.182.201@853#iana.tenta.io">99.192.182.201@853#iana.tenta.io</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:99.192.182.100@853#opennic.tenta.io">99.192.182.100@853#opennic.tenta.io</a><br>
        forward-addr: <a class="moz-txt-link-abbreviated" href="mailto:99.192.182.101@853#opennic.tenta.io">99.192.182.101@853#opennic.tenta.io</a> <br>
        forward-tls-upstream: yes<br>
      <br>
      # OpenDNS is NOT DNSSEC enabled<br>
      server: auto-trust-anchor-file: "C:\Program
      Files\Unbound\root.key"<br>
      ###<br>
    </p>
    <div class="moz-cite-prefix">21.07.2019 21:37, RayG via
      Unbound-users пишет:<br>
    </div>
    <blockquote type="cite"
cite="mid:!&!AAAAAAAAAAAuAAAAAAAAAKBDd+9FwARDm92XJEsqgNgBAMO2jhD3dRHOtM0AqgC7tuYAAAAAAA4AABAAAADNXVYnZh5wQ7qw0mMNg5KAAQAAAAA=@btinternet.com">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"Lucida Console";
        panose-1:2 11 6 9 4 5 4 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
code
        {mso-style-priority:99;
        font-family:"Lucida Console";
        color:#333333;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal">Hi,<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN">I have configured things so far but I get these
              errors and I think the reason is the “tls-cert-bundle”
              setting.<o:p></o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN"><o:p> </o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN">16:10:16 C:\Program
              Files\Unbound\unbound.exe[1740:0] error: ssl handshake
              failed crypto error:1416F086:SSL
              routines:tls_process_server_certificate:certificate verify
              failed<o:p></o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN">21/07/2019<o:p></o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN"><o:p> </o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN">So to get this working I have to enable this
              setting:<o:p></o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN"><o:p> </o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN">tls-cert-bundle:
              /etc/ssl/certs/ca-certificates.crt<o:p></o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN"><o:p> </o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN">That example would seem OK for a UNIX install
              but where/how do I configure this for windows?<o:p></o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN"><o:p> </o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN">Can I use the windows certificate store? If so
              what would the entry read.<o:p></o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN"><o:p> </o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN">Thanks<o:p></o:p></span></code></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal"><span style="mso-fareast-language:EN-GB">Regards<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="mso-fareast-language:EN-GB">Ray<o:p></o:p></span></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN"><o:p> </o:p></span></code></p>
        <p class="MsoNormal"><code><span style="font-size:10.0pt"
              lang="EN"><o:p> </o:p></span></code></p>
      </div>
    </blockquote>
    <pre class="moz-signature" cols="72">-- 
"C++ seems like a language suitable for firing other people's legs."

*****************************
* C++20 : Bug to the future *
*****************************</pre>
  </body>
</html>