forward-zone without revalidation

Marek Vavruša marek at
Tue Jun 28 23:54:41 CEST 2016

Hey, is there a way to do forward-zone but without revalidation of DNSSEC?
I don't mean NTAs, but I'd like to either trust the forward-host(s), or do
DNSSEC validation in Unbound if the forwarder doesn't work. Am I missing
something or it's not supported?

