Maintained by: NLnet Labs

[Unbound-users] DNSSEC mismatch between Bind 9.7 and Unbound

Florian Weimer
Sat Nov 6 17:42:17 CET 2010

* Tony Finch:

> On Fri, 5 Nov 2010, W.C.A. Wijngaards wrote:
>> The trouble is that bind does not respond with the correct response to
>> the query for the DS.  Unbound can do nothing but fail the query.
> Isn't the more fundamental problem that someone tried to put a CNAME at
> the zone apex of

Yes, but it's still a major bug if correctly signing a parent makes
non-signed child zones unavailable which have been working before.