We just left the dnssec-lookaside auto; configuration in there. Probably because it specifically says in the documentation from ISC that it won't hurt anything to leave it in there... # Configuring "dnssec-lookaside auto;" to activate this key is # harmless Guess not? Thanks, -Drew -----Original Message----- From: Stephane Bortzmeyer <bortzmeyer@nic.fr> Sent: Wednesday, March 25, 2020 1:27 PM To: Drew Weaver <drew.weaver@thenap.com> Cc: 'nanog@nanog.org' <nanog@nanog.org> Subject: Re: ISC BIND 9 breakage? On Wed, Mar 25, 2020 at 05:18:49PM +0000, Drew Weaver <drew.weaver@thenap.com> wrote a message of 97 lines which said:
Did anyone else on CentOS 6 just have some DNS resolvers totally fall over?
dlv.isc.org signatures just expired.
# NOTE: The ISC DLV zone is being phased out as of February 2017;
And yet some people still use it, it seems.