Skip to Content.
Sympa Menu

discuss - [opennic-discuss] unbound tier 2 / personal not working. errors hints file SERVFAIL security failure

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

[opennic-discuss] unbound tier 2 / personal not working. errors hints file SERVFAIL security failure


Chronological Thread  
  • From: <register2021 AT dimtim.eu>
  • To: discuss AT lists.opennicproject.org
  • Subject: [opennic-discuss] unbound tier 2 / personal not working. errors hints file SERVFAIL security failure
  • Date: Thu, 20 Jan 2022 20:24:11 +0100

Hello,
I have installed personal unbound resolver on Ubuntu 20.04 with default
configuration and it works OK in my home network.
When i add just 1 line:
root-hints: "/etc/unbound/opennic.cache"
to the unbound.conf, my server starts with status OK, but stops resolving and
gives SERVFAIL errors on dig commands. This line breaks it. When i comment it
out, after restart it works properly (but of course, not seeing opennic
domains).

journalctl -xe
gives multiple errors of this type:
info: failed to prime trust anchor -- DNSKEY rrset is not secure . DNSKEY IN

also:
unbound-host -C /etc/unbound/unbound.conf -v sigok.verteiltesysteme.net
sigok.verteiltesysteme.net has address 134.91.78.139 (BOGUS (security
failure))
validation failure <sigok.verteiltesysteme.net. A IN>: signature missing from
161.97.219.84 for trust anchor . while building chain of trust
sigok.verteiltesysteme.net has IPv6 address 2001:638:501:8efc::139 (BOGUS
(security failure))

Do you support widely used, actively developed and easy to configure unbound
resolver? It looks you don't.. I did not find any post here when i searched
for "unbound".
Do you plan to support it?
Thanks



Archive powered by MHonArc 2.6.24.

Top of Page