Rick van Rein <[email protected]> wrote:
>
> I *think* I am asking for something new — namely, to insist on presence
> of DNSSEC and proper validation on it. In other words, to be able to
> neglect anything that is not properly signed.
Not that new - look at BIND's dnssec-must-be-secure option.
Tony.
--
f.anthony.n.finch <[email protected]> http://dotat.at/
Forties, Cromarty: East, veering southeast, 4 or 5, occasionally 6 at first.
Rough, becoming slight or moderate. Showers, rain at first. Moderate or good,
occasionally poor at first.
_______________________________________________
Unbound-users mailing list
[email protected]
http://unbound.nlnetlabs.nl/mailman/listinfo/unbound-users