broken trust chain

Jeremy C. Reed reed at reedmedia.net
Mon Sep 28 14:35:44 UTC 2020


Let's get more logging. Enable more debugging in named.
What made named think that name should be DNSSEC signed in the first 
place?

Do you only have the problem resolving the single name and it doesn't 
happen every time?
Does the problem ever happen without using your forwarders?

Also do the query with delv -d99 and record that verbose output.


More information about the bind-workers mailing list