[Unbound-users] "Tunnel" dnssec through local forward-zone?
leen at consolejunkie.net
Tue Jul 26 22:18:43 UTC 2011
On 07/26/2011 06:11 PM, Paul Wouters wrote:
> On Tue, 26 Jul 2011, Leen Besselink wrote:
>> Are you sure 126.96.36.199 supports DNSSEC ? Because than I would have
>> expected this to work:
>> $ cat /etc/resolv.conf
>> nameserver 188.8.131.52
>> $ ./unbound-host -h | grep Version # with ldns-1.6.10 and only one
>> configure option: --disable-gost
>> Version 1.4.12
> note unbound-host uses configuration from /etc/unbound/unbound.conf
> and not the system
That is why I had use the -r as an argument to the unbound-host command.
> You're right, google does not yet fully support all DNSSEC records. It
> does support
> returning RRSIGs and DNSKEYs but it does not seem to support DS
> records yet.
I guess it doesn't know it needs to talk to the nameservers of the
parentzone to get the DS ?
More information about the Unbound-users