missing mandatory glue for root nameservers in BIND 9.21.26 global forwarding configuration

Colin Vidal colin at isc.org
Mon Sep 28 09:05:31 UTC 2026


On Mon, 2026-09-28 at 10:57 +0200, Colin Vidal via bind-users wrote:
>  (Although I'd expect priming to _not_ run on the
> latest BIND dev release in such case, especially because it's
> useless.
> I'll need to check this out.)

Ah, I see. The resolver itself doesn't issue priming on forward only
(as I expected), but the DNSSEC validation triggers it as a side
effect. This needs to be fixed otherwise this would badly pollute the
logs. (And keeping a priming failure on the log by default sound
sensible, as this might be critical.)

I'll create an issue for this. Thanks.

-- 
Colin Vidal -- colin at isc.org
Internet Systems Consortium


More information about the bind-users mailing list