DNSSEC discussion - support for proxy-dnssec

Pi-hole version is v5.16.2 (Latest: v5.16.2)
AdminLTE version is v5.19 (Latest: v5.19)
FTL version is new/ede-dnssec vDev-d228fbf (Latest: v5.22)


(more entries - all OK - not in screenshot)

AMAZING!!!

FTL.zip (29.2 KB) (log and pcap)

All FTL tests (using NSD) complete successfully (json test data included)
testftl.zip (2.2 KB)

summary:

  • added to unbound:
	# required for proxy-dnssec (dnsmasq)
	# https://nlnetlabs.nl/news/2022/Jun/02/unbound-1.16.0-released/
	# https://blog.nlnetlabs.nl/extended-dns-error-support-for-unbound/
	ede: yes

added to dnsmasq (ensure DNSSEC isn't enabled in settings!)

# requires use of "ede: yes" in unbound.conf
proxy-dnssec
add-cpe-id=01234

grafana:

THANKS for your time, effort, persistence !!!

1 Like