How do I debug if the queries are not getting resolved?

Stacey Marshall stacey.marshall at gmail.com
Wed Dec 13 10:23:16 UTC 2023


That's good advice Greg, I thought I'd read up some more about that in the DNSSEC guide within the Admin. Reference Manual - https://bind9.readthedocs.io/en/v9.18.20/dnssec-guide.html - only it is not mentioned within that section (dnssec-validation is).  It is in the Configuration Reference - https://bind9.readthedocs.io/en/v9.18.20/reference.html#namedconf-statement-validate-except - right under dnssec-validation (which ideally would mention it too).

I've create an enhancement request
https://gitlab.isc.org/isc-projects/bind9/-/issues/4489

--
Stace

On 12 Dec 2023, at 18:00, Greg Choules via bind-users wrote:

> I really wouldn't recommend that.
> If you have to, create exceptions for domains that won't validate correctly by using the "validate-except {..." statement.
> In parallel with that, encourage people with broken domains to fix them, which makes life better for all of us.
>
> Cheers, Greg
>
> On Tue, 12 Dec 2023 at 17:42, Blason R <blason16 at gmail.com> wrote:
>
>> Thanks folks
>>
>> I just disabled DNSSEC validation from bind config file (globally) and
>> those domains started resolving fine.
>>
>>


More information about the bind-users mailing list