Hi chris,

You are correct.
Enabling validator module effectively enables DNSSEC.
If you only cache internal network dns entries, there is not much added value 
enabling validator as far as I can see.

Cheers,
Mike
-----Original Message-----
From: [email protected] 
[mailto:[email protected]] On Behalf Of Chris Smith
Sent: Monday, 21 February 2011 17:44
To: [email protected]
Subject: [Unbound-users] validator module

Is the validator module only for DNSSEC validation?

If so, is there any benefit (less overhead) to running Unbound with only the 
iterator module:
module-config: "iterator"
when you're basically operating as a local cache for the network working with 
stub-zones and forwarders that are not using DNSSEC?

Thank you,

Chris
_______________________________________________
Unbound-users mailing list
[email protected]
http://unbound.nlnetlabs.nl/mailman/listinfo/unbound-users

********************************************************************************
 
 
N.B.: op (de inhoud van) deze e-mail is een DISCLAIMER met belangrijke 
VOORBEHOUDEN van toepassing: zie http://www.t-mobile.nl/disclaimer 
 
This e-mail and its contents are subject to a DISCLAIMER with important 
RESERVATIONS: see http://www.t-mobile.nl/disclaimer 
  
 
********************************************************************************
 


_______________________________________________
Unbound-users mailing list
[email protected]
http://unbound.nlnetlabs.nl/mailman/listinfo/unbound-users

Reply via email to