unbound keeps restarting due to DNSSEC, can't change config (solved)

  • I've got a new 2.4.3_1 stable install and unbound keeps restarting with this in the logs.

    info: failed to prime trust anchor -- DNSKEY rrset is not secure . DNSKEY IN

    If I try to disable DNSSEC I get errors about missing files in /var/unbound/test/ and it won't accept the GUI config change.

    My solution was to ssh in, create /var/unbound/test and copy all the "unbound*" files from /var/unbound into it. I think it just uses the key files but I didn't spend a lot of time investigating it. With that done it accepted the config and I could turn DNSSEC off.

    Hope that helps somebody.

