Re: [Unbound-users] Servers for local zones that are not signed

2012-07-06 Thread W.C.A. Wijngaards
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Eugene, On 07/06/2012 02:25 PM, Eugene Crosser wrote: On 07/06/2012 03:33 PM, Jan-Piet Mens wrote: So unbound asks dnsmasq for the address of myhost.lan as it is instructed by forward-zone, gets correct result (!), but then marks it bogus

Re: [Unbound-users] Servers for local zones that are not signed

2012-07-06 Thread Eugene Crosser
On 07/06/2012 04:45 PM, W.C.A. Wijngaards wrote: So unbound asks dnsmasq for the address of myhost.lan as it is instructed by forward-zone, gets correct result (!), but then marks it bogus because it cannot establish trust chain. You'll need private-domain: lan. domain-insecure: lan.