Another problem: switching from forwarders to authority does not clean Unbound

Phil Regnauld regnauld at nsrc.org
Sat Oct 29 16:57:26 UTC 2011

Stephane Bortzmeyer (bortzmeyer) writes:
> So, apparently, something is not cleaned from the time were Unbound,
> using forwarders, were not receiving expected RRSIGs. I assume
> dnssec-trigger does not expect the resolvers to change behavior but
> reprobing should "reset" Unbound more completely.

	You'd have to keep track of the names for which you've just
	probed and issue a unbound-control flush <name> - short
	of doing unbound-control flush_zone . (ugh, big hammer).

