Matthijs,
It does not look a permission problem to me: the log message appears
because ldns_axfr_next() could not get a RR from the AXFR.
The most obvious reasons for this failure are
- - the wire could not be converted to the ldns packet structure (for
example, a RR could not be parsed)
- - the RCODE does not equal NOERROR
I consider that a bit doubtful: the zone is served by BIND 9.7.2-P3 and
contains nothing terribly exciting in the way of RR. Furthermore Unbound
can query any record in those zones.
Additionally, as shown in a message a few minutes ago, increasing the
verbosity of the signer triggers a successful AXFR ...
-JP
_______________________________________________
Opendnssec-user mailing list
[email protected]
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user