1
General Discussion / Re: DNSSEC Enabled, but not configured correctly
« on: May 13, 2023, 01:14:11 pm »
Thank you for your response.
No, no root.key in that folder, only has two files; unbound.conf and unbound.conf.sample
They are both exactly the same, all the potential variables are commented out.
I did find the folder; '/var/unbound/'
Which does contain 'root.key', modified date is today, and has an unbound.conf which contains; 'auto-trust-anchor-file: /var/unbound/root.key'
Odd, I was hoping it would be missing that or be old, so that it would be a clear fix.
The root key appears to be up to date, hash matches IANA
No, no root.key in that folder, only has two files; unbound.conf and unbound.conf.sample
They are both exactly the same, all the potential variables are commented out.
I did find the folder; '/var/unbound/'
Which does contain 'root.key', modified date is today, and has an unbound.conf which contains; 'auto-trust-anchor-file: /var/unbound/root.key'
Odd, I was hoping it would be missing that or be old, so that it would be a clear fix.
Code: [Select]
zxuilnie@opnsense:~ % unbound-anchor -a /var/unbound/root.key -l
. IN DS 20326 8 2 E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D
The root key appears to be up to date, hash matches IANA