> We have "solved" the problem by > setting the internal Unbound to not validate and let the forwarder > do the DNSSEC work. That would be a neat feature for DNSSEC-Trigger: detect that the upstream forwarder is Unbound (version.bind chaos txt) and disable the validator. Well, maybe not. :-) -JP