Tuesday, August 04, 2020

unwind, is it possible to prevent validation failures?

Hi,

Aug 5 07:09:55 beta unwind[1703]: startup
Aug 5 07:09:59 beta unwind[62921]: validation failure <eta.internal.centroid.eu
. A IN>: no DNSSEC records from 192.168.177.1 for DS internal.centroid.eu. while
building chain of trust

Let me describe my setup. Here is my unwind.conf:

beta# more /etc/unwind.conf
forwarder 192.168.177.1
preference forwarder

At 192.168.177.1 runs a forwarding delphinusdnsd (snapshot version). It has
some internal zones, such as: internal.centroid.eu, petphi.centroid.eu, these
are not zones that are on the big Internet and thus have no DNSSEC.

unwind is being overly picky about this it seems. Is there a way to tell it,
to not try to validate these internal zones?

I'm running on 6.7.

Best Regards,
-peter

No comments:

Post a Comment