Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unbound + DNSSEC + Domain Overrides

    DHCP and DNS
    6
    7
    4.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      azekiel
      last edited by

      Hi guys,

      just noticed that if you have a domain override for some internal domain ("example.local") and DNSSEC enabled at the same time the unbound server does respond with SERVFAIL.

      You have to include

      
      server:
      private-domain:"example.local"
      domain-insecure:"example.local"
      
      

      for every domain.

      This is correct, because these domains are not validated by DNSSEC. But this should happen automatically if you add a domain override (or a checkbox where you can control it) in my opinion.

      Greets

      1 Reply Last reply Reply Quote 2
      • BismarckB
        Bismarck
        last edited by

        Just want to say thank you, this saved me some headaches and I agree, this should be added automatically, when enebling DNSSEC with domain overrides existing.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          How is what??

          This would only fail if the dnssec on that domain is not valid.. If it does not have any dnssec enabled than it would work just fine.  So yeah if your pointing an override where a domain has a broken dnssec setup then yeah it would give you servfail.

          If what your saying was true then unbound wouldn't work for any domain that is not dnssec enabled..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            It's not required to disable DNSSEC for forwarded domains, so it would be inappropriate to do so automatically. At some point I might add a checkbox to the domain override screen to add it automatically, disabled by default.

            1 Reply Last reply Reply Quote 0
            • A
              azekiel
              last edited by

              @cmb:

              It's not required to disable DNSSEC for forwarded domains, so it would be inappropriate to do so automatically. At some point I might add a checkbox to the domain override screen to add it automatically, disabled by default.

              I'm gonna check that again.

              "example.local" was some internal Windows DNS Server for that Active Directory domain for me. I don't think that there was/is DNSSEC enabled.

              1 Reply Last reply Reply Quote 0
              • N
                Napsterbater
                last edited by

                I know this is old but...

                @azekiel said in Unbound + DNSSEC + Domain Overrides:

                Hi guys,

                just noticed that if you have a domain override for some internal domain ("example.local") and DNSSEC enabled at the same time the unbound server does respond with SERVFAIL.

                You have to include

                
                server:
                private-domain:"example.local"
                domain-insecure:"example.local"
                
                

                @azekiel said in Unbound + DNSSEC + Domain Overrides:

                @cmb:

                It's not required to disable DNSSEC for forwarded domains, so it would be inappropriate to do so automatically. At some point I might add a checkbox to the domain override screen to add it automatically, disabled by default.

                I'm gonna check that again.

                "example.local" was some internal Windows DNS Server for that Active Directory domain for me. I don't think that there was/is DNSSEC enabled.

                I JUST ran into this EXACT same problem on pfSense 2.4.4 p1.

                Also doing a Domain Override on a Windows AD Domain with NO DNSSEC setup on it once so ever, not a Broken DNSSEC, NO DNSSEC.

                Unbound kept replying SERVFAIL with no real explanation in the logs.

                Adding domain-insecure:"example.local" fixed mine as well.

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  Using something like dig or drill can help diagnose this sort of problem. There is far more to diagnosing DNS issues than looking at unbound logs.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.