Hi Paul,
This was caused by copy of the setting at initialisation, but now I've
fixed it so that it uses the config structure, and unbound-control
should be able to control val-permissive-mode (combine with flush_bogus
to remove the cached validation failures), and val-clean-additional.
Best
I tried the following:
service unbound restart
sudo unbound-control set_option val-permissive-mode: yes
dig www.dnssec-failed.org
But that still gives a servfail.
Sprinking various flush_* options also did not seem to help.
Is this a bug or a feature? :)
Setting val-permissive-mode: yes in