Matthijs,

It does not look a permission problem to me: the log message appears
because ldns_axfr_next() could not get a RR from the AXFR.

The most obvious reasons for this failure are
- - the wire could not be converted to the ldns packet structure (for
example, a RR could not be parsed)
- - the RCODE does not equal NOERROR

I consider that a bit doubtful: the zone is served by BIND 9.7.2-P3 and contains nothing terribly exciting in the way of RR. Furthermore Unbound can query any record in those zones.

Additionally, as shown in a message a few minutes ago, increasing the verbosity of the signer triggers a successful AXFR ...

        -JP

_______________________________________________
Opendnssec-user mailing list
[email protected]
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user

Reply via email to