> We have "solved" the problem by
> setting the internal Unbound to not validate and let the forwarder
> do the DNSSEC work.
That would be a neat feature for DNSSEC-Trigger: detect that the
upstream forwarder is Unbound (version.bind chaos txt) and disable the
validator. Well, maybe not. :-)
-JP