This bug silently deactivate DNSSEC on systems where Unbound is installed. The system will fallback to the default resolver and happily resolve dns queries with invalid signatures.
This should be marked as a security issue. Problem resolved (no pun intended) with the provided patch, then reloading the apparmor configuration. systemctl reload apparmor.service systemctl restart unbound.service -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1723900 Title: unbound systemctl (re)start fails due to Apparmor profile issue To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/unbound/+bug/1723900/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
