Load a certificate without restart

2018-01-04 Thread Sebastian Schmidt via Unbound-users
Hello,  I'm wondering if unbound has a method where a new certificate can be loaded without restarting unbound. This would be helpful when loading for short-lived (1 day) DNSCrypt certificates and potentially for TLS certs from Let's Encrypt (3 Months). Ideally unbound would run forever

Re: wildcard dnssec test fails

2017-12-15 Thread Sebastian Schmidt via Unbound-users
lso need the > code change. So that won't work as a workaround. > > Best regards, Wouter > > On 15/12/17 11:40, W.C.A. Wijngaards via Unbound-users wrote: > > Hi Sebastian > > > > On 15/12/17 10:19, Sebastian Schmidt via Unbound-users wrote: > >> On

Re: wildcard dnssec test fails

2017-12-15 Thread Sebastian Schmidt via Unbound-users
On 15 December 2017 at 6:09:19 pm, W.C.A. Wijngaards via Unbound-users (unbound-users@unbound.net) wrote: When I run unbound-host, I get no errors,  ./unbound-host  www.wilda.nsec.0skar.czwww.wilda.nsec.0skar.cz -f  root.key -v -t A  www.wilda.nsec.0skar.czwww.wilda.nsec.0skar.cz has address 

Re: wildcard dnssec test fails

2017-12-14 Thread Sebastian Schmidt via Unbound-users
Hi Paul, > Is your unbound configured to use another DNS as forwarder? Yes, to nsd for opennic TLDs which to my understanding should not impact this query. Here is the config file: # This file is managed by Ansible. # # template:

wildcard dnssec test fails

2017-12-13 Thread Sebastian Schmidt via Unbound-users
Hello, I’ve unbound setup on FreeBSD 11.1 and I can’t figure out why "drill www.wilda.nsec.0skar.cz" gives SERVFAIL. The domain is from this (http://0skar.cz/dns/en) test site where it reports three failures (2a, 2b and 4). Any help would be appreciated. Thanks Sebastian $ unbound -h