Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    unbound keeps restarting due to DNSSEC, can't change config (solved)

    Scheduled Pinned Locked Moved DHCP and DNS
    1 Posts 1 Posters 411 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y
      yoyo42
      last edited by

      I've got a new 2.4.3_1 stable install and unbound keeps restarting with this in the logs.

      info: failed to prime trust anchor -- DNSKEY rrset is not secure . DNSKEY IN
      

      If I try to disable DNSSEC I get errors about missing files in /var/unbound/test/ and it won't accept the GUI config change.

      My solution was to ssh in, create /var/unbound/test and copy all the "unbound*" files from /var/unbound into it. I think it just uses the key files but I didn't spend a lot of time investigating it. With that done it accepted the config and I could turn DNSSEC off.

      Hope that helps somebody.

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.