# Unbound 1.9.2 released (june 17)

**URL:** <https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881>\
**Category:** General\
**Created:** [June 19, 2019, 7:57am UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881 "2019-06-19T07:57:56Z")\
**Posts on this page:** 17\
**Page:** 2

<div class="post-metadata">

**Author:** ![jpgpi250](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jpgpi250/32/286_2.png) [@jpgpi250](https://discourse.pi-hole.net/u/jpgpi250)\
**Post date:** [June 20, 2019, 2:49pm UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/25 "2019-06-20T14:49:21Z")

</div>

> [@ajp2k17](#):
>
> I can’t seem to get qname minimization to work when compiling 1.9.2.

**unbound** (127.10.10.2 -p 5552):

```auto
dig @127.10.10.2 -p 5552 txt qnamemintest.internet.nl

; <<>> DiG 9.10.3-P4-Raspbian <<>> @127.10.10.2 -p 5552 txt qnamemintest.internet.nl
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 7577
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 1, ADDITIONAL: 3

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1472
;; QUESTION SECTION:
;qnamemintest.internet.nl. IN TXT

;; ANSWER SECTION:
qnamemintest.internet.nl. 3600 IN CNAME a.b.qnamemin-test.internet.nl.
a.b.qnamemin-test.internet.nl. 3600 IN TXT "HOORAY - QNAME minimisation is enabled on your resolver :)!"

;; AUTHORITY SECTION:
a.b.qnamemin-test.internet.nl. 3600 IN NS ns.a.b.qnamemin-test.internet.nl.

;; ADDITIONAL SECTION:
ns.a.b.qnamemin-test.internet.nl. 3600 IN AAAA 2a04:b900::8:0:0:63
ns.a.b.qnamemin-test.internet.nl. 3600 IN A 185.49.140.63

;; Query time: 132 msec
;; SERVER: 127.10.10.2#5552(127.10.10.2)
;; WHEN: Thu Jun 20 16:42:54 CEST 2019
;; MSG SIZE rcvd: 218

```

**knot-resolver** (127.10.10.5 -p 5555):

```auto
dig @127.10.10.5 -p 5555 txt qnamemintest.internet.nl

; <<>> DiG 9.10.3-P4-Raspbian <<>> @127.10.10.5 -p 5555 txt qnamemintest.internet.nl
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 425
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;qnamemintest.internet.nl. IN TXT

;; ANSWER SECTION:
qnamemintest.internet.nl. 3361 IN CNAME a.b.qnamemin-test.internet.nl.
a.b.qnamemin-test.internet.nl. 3361 IN TXT "HOORAY - QNAME minimisation is enabled on your resolver :)!"

;; Query time: 0 msec
;; SERVER: 127.10.10.5#5555(127.10.10.5)
;; WHEN: Thu Jun 20 16:43:53 CEST 2019
;; MSG SIZE rcvd: 157

```

content of **/etc/unbound/unbound.conf.d/qname-minimisation.conf** :

```auto
server:
    # Send minimum amount of information to upstream servers to enhance
    # privacy. Only sends minimum required labels of the QNAME and sets
    # QTYPE to NS when possible.

    # See RFC 7816 "DNS Query Name Minimisation to Improve Privacy" for
    # details.
	
	# https://ripe72.ripe.net/presentations/120-unbound_qnamemin_ripe72.pdf
	# test: drill txt qnamemintest.internet.nl
	# result: "HOORAY - QNAME minimisation is enabled on your resolver :)!"

    qname-minimisation: yes
    harden-below-nxdomain: yes

```

---

<div class="post-metadata">

**Author:** ![ajp2k17](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/a/ac91a4/32.png) [@ajp2k17](https://discourse.pi-hole.net/u/ajp2k17)\
**Post date:** [June 20, 2019, 2:57pm UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/26 "2019-06-20T14:57:02Z")

</div>

Thanks, I had exactly that config but it was on a Diet-Pi installation. I will try with normal Raspbian light as well.

---

<div class="post-metadata">

**Author:** ![ajp2k17](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/a/ac91a4/32.png) [@ajp2k17](https://discourse.pi-hole.net/u/ajp2k17)\
**Post date:** [June 20, 2019, 3:43pm UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/28 "2019-06-20T15:43:22Z")

</div>

> [@jpgpi250](#):
>
> **unbound** (127.10.10.2 -p 5552):

Got it working now, weird!

Any idea why I get a bunch of these in my logs?

Jun 20 17:37:40 unbound[403:0] info: error sending query to auth server 198.97.190.53 port 53  
Jun 20 17:37:40 unbound[403:0] info: error sending query to auth server 193.0.14.129 port 53  
Jun 20 17:37:40 unbound[403:0] info: error sending query to auth server 193.0.14.129 port 53  
Jun 20 17:37:40 unbound[403:0] info: error sending query to auth server 198.97.190.53 port 53  
Jun 20 17:37:40 unbound[403:0] info: error sending query to auth server 192.203.230.10 port 53  
Jun 20 17:37:40 unbound[403:0] info: error sending query to auth server 192.203.230.10 port 53  
Jun 20 17:37:40 unbound[403:0] info: error sending query to auth server 192.36.148.17 port 53  
Jun 20 17:37:40 unbound[403:0] info: error sending query to auth server 192.33.4.12 port 53  
Jun 20 17:37:40 unbound[403:0] info: error sending query to auth server 193.0.14.129 port 53  
Jun 20 17:37:40 unbound[403:0] info: error sending query to auth server 192.203.230.10 port 53

---

<div class="post-metadata">

**Author:** ![jpgpi250](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jpgpi250/32/286_2.png) [@jpgpi250](https://discourse.pi-hole.net/u/jpgpi250)\
**Post date:** [June 20, 2019, 5:58pm UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/29 "2019-06-20T17:58:06Z")

</div>

> [@ajp2k17](#):
>
> Any idea why I get a bunch of these in my logs?

NOT in my logs.  
What is your verbose setting?

---

<div class="post-metadata">

**Author:** ![ajp2k17](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/a/ac91a4/32.png) [@ajp2k17](https://discourse.pi-hole.net/u/ajp2k17)\
**Post date:** [June 20, 2019, 6:26pm UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/30 "2019-06-20T18:26:25Z")

</div>

Verbosity is set to 1. If I delete root.zone and start over it looks fine I think, then if I reboot the log messages start to appear.

---

<div class="post-metadata">

**Author:** ![jpgpi250](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jpgpi250/32/286_2.png) [@jpgpi250](https://discourse.pi-hole.net/u/jpgpi250)\
**Post date:** [June 20, 2019, 7:21pm UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/31 "2019-06-20T19:21:32Z")

</div>

> [@ajp2k17](#):
>
> If I delete root.zone

you can (have to ?) update the local copy of the root zone using the command:

```auto
sudo /usr/sbin/unbound-control auth_zone_transfer "."

```

I do this on a weekly basis, using cron, also updating the root.hints

You can also increase / decrease the verbose setting using the command:

```auto
sudo /usr/sbin/unbound-control verbosity x

```

x being any number between 0 and ? (I've gone as high as 5)

`edit`  
using the above command eliminates the need to restart unbound, you'll see an entry in the log, if successful.  
`/edit`

In order for this to work, you need to have the following in your unbound.conf file:

```auto
# Remote control config section.
remote-control:
	control-enable: yes

```

Script I run with cron (way to complex, I know):

```auto
#!/usr/bin/env bash

# Make sure only root can run our script
if ["$(id -u)" != "0"]; then
  echo "This script must be run as root" 1>&2
  exit 1
fi

# compiled version of unbound v1.9.2
if [-f /etc/unbound/root.hints]
then
   # unbound
   sudo wget https://www.internic.net/domain/named.root -O /etc/unbound/root.hints
fi
if [-f /etc/unbound/root.zone]
then
   # zone transfert
   echo 'zone transfert "."'
   sudo /usr/sbin/unbound-control auth_zone_transfer "."
fi

# Raspbian version of unbound v1.6.0
if [-f /var/lib/unbound/root.hints]
then
   # unbound
   sudo wget https://www.internic.net/domain/named.root -O /var/lib/unbound/root.hints
fi

```

---

<div class="post-metadata">

**Author:** ![ajp2k17](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/a/ac91a4/32.png) [@ajp2k17](https://discourse.pi-hole.net/u/ajp2k17)\
**Post date:** [June 20, 2019, 8:49pm UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/33 "2019-06-20T20:49:58Z")

</div>

Thanks for the help, much appreciated! I'll give it a try... 🙂

---

<div class="post-metadata">

**Author:** ![Gizmo\_Ger](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/gizmo_ger/32/8032_2.png) [@Gizmo\_Ger](https://discourse.pi-hole.net/u/Gizmo_Ger)\
**Post date:** [June 21, 2019, 9:27pm UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/34 "2019-06-21T21:27:09Z")

</div>

I followed the link above and compiled from scratch. Although i double checked the unbound.conf I can´t get it to work. unbound -v gave me "can´t bind socket". I´m running armbian on rock64. Looks like I have to stick to the default package.

---

<div class="post-metadata">

**Author:** ![jpgpi250](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jpgpi250/32/286_2.png) [@jpgpi250](https://discourse.pi-hole.net/u/jpgpi250)\
**Post date:** [June 22, 2019, 6:52am UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/35 "2019-06-22T06:52:28Z")

</div>

> [@Gizmo\_Ger](#):
>
> can´t bind socket

My unbound configuration [here](https://discourse.pi-hole.net/t/anyone-using-knot-resolver/19750/29).

If you are using the IPv4 only configuration, you will NOT be able to use the default package either, the same error will occur.

Ipv4 only config:

```auto
    interface: 127.10.10.2@5552
    do-ip4: yes
    do-udp: yes
    do-tcp: yes
    do-ip6: no

```

If you are using both IPv4 and IPv6, you need to ensure **the IPv6 address exists** , before starting unbound, as opposed to the IPv4 addresses I use (127.10.10.x), which do NOT need to exist before starting unbound.

IPv4 & IPv6 configuration:

```auto
    interface: 127.10.10.2@5552
    interface: fdaa:bbcc:ddee:2::5552@5552
    do-ip4: yes
    do-udp: yes
    do-tcp: yes
    do-ip6: yes

```

I've been using a "dirty", probably unapproved, method to ensure the IPv6 address exists, even after a reboot:

```auto
sudo ip -6 addr add fdaa:bbcc:ddee:2::5552/128 dev eth0
sudo sed -i '0,/^e-i xit 0.*/s/^exit 0.*/sudo ip -6 addr add fdaa:bbcc:ddee:2::5552\/128 dev eth0\n&/' /etc/rc.local

```

First line adds the IPv6 address immediately, after this you should be able to start unbound.  
Second line adds the command to `/etc/rc.local`, which is executed during reboot.

---

<div class="post-metadata">

**Author:** ![Gizmo\_Ger](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/gizmo_ger/32/8032_2.png) [@Gizmo\_Ger](https://discourse.pi-hole.net/u/Gizmo_Ger)\
**Post date:** [June 22, 2019, 7:44am UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/36 "2019-06-22T07:44:02Z")

</div>

You are right. I´m running IP4 only. I´ll try again and keep you posted. Thanks for hinting me in the right direction.

---

<div class="post-metadata">

**Author:** ![jpgpi250](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jpgpi250/32/286_2.png) [@jpgpi250](https://discourse.pi-hole.net/u/jpgpi250)\
**Post date:** [June 22, 2019, 7:56am UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/37 "2019-06-22T07:56:32Z")

</div>

Don't give up to soon!

Something else you might not know (yet):  
The instructions I provided to compile unbound, result in unbound, running with chroot.  
As far as I understand this (NOT a Linux expert), this is more secure, unbound can't get to anything outside it's own directory.  
What this means:  
The unbound configuration files are located in `/etc/unbound`. As far as unbound is aware, this is the root. This means, for example, you have to configure unbound to keep the logfile somewhere in`/etc/unbound` or below. The configuration file however will show:

```auto
logfile: /unbound.log

```

All file reference are relative to `/etc/unbound`.

---

<div class="post-metadata">

**Author:** ![Gizmo\_Ger](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/gizmo_ger/32/8032_2.png) [@Gizmo\_Ger](https://discourse.pi-hole.net/u/Gizmo_Ger)\
**Post date:** [June 22, 2019, 8:39am UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/38 "2019-06-22T08:39:37Z")

</div>

Naw, I won´t give up that soon.  
I managed to set up everything, double checked but still getting this:

root@rock64:~# unbound -v  
[1561192621] unbound[1643:0] notice: Start of unbound 1.9.2.  
Jun 22 10:37:01 unbound[1643:0] error: can't bind socket: Address already in use for 127.0.0.1 port 8953  
Jun 22 10:37:01 unbound[1643:0] error: cannot open control interface 127.0.0.1 8953  
Jun 22 10:37:01 unbound[1643:0] fatal error: could not open ports

I have no clue where that port comes from. I explicitly pointed to local interface and port #5353 in unbound.conf

---

<div class="post-metadata">

**Author:** ![jpgpi250](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jpgpi250/32/286_2.png) [@jpgpi250](https://discourse.pi-hole.net/u/jpgpi250)\
**Post date:** [June 22, 2019, 8:57am UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/39 "2019-06-22T08:57:58Z")

</div>

> [@Gizmo\_Ger](#):
>
> Address already in use for 127.0.0.1 port 8953

Again, I'm NOT a Linux expert, just trying.

On my system, running pihole + unbound 1.9.2, when I enter `sudo netstat -tulpen | grep 8953`, I get the result:

```auto
sudo netstat -tulpen | grep 8953
tcp 0 0 127.0.0.1:8953 0.0.0.0:* LISTEN 0 990113 4080/unbound
tcp6 0 0 ::1:8953 :::* LISTEN 0 990112 4080/unbound

```

DuckDuck go says [here](http://www.t1shopper.com/tools/port-number/8953/), this is a port, used by unbound.

`edit`  
**Also port 5353 is already in use by the avahi-daemon**

```auto
sudo netstat -tulpen | grep 5353
udp 0 0 0.0.0.0:5353 0.0.0.0:* 108 11592 407/avahi-daemon: r
udp6 0 0 :::5353

```

`/edit`

As a NON linux expert, I would conclude unbound is already running.  
To verify this:  
`sudo service unbound status`  
To stop the already running unbound:  
`sudo service unbound stop`

Commands I use to check if unbound is working (replace port and IP):  
`dig @127.10.10.2 -p 5552 +dnssec www.raspberrypi.org`

If you followed my instructions to compile unbound, you should have created `/lib/systemd/system/unbound.service` (+daemon reload & enable service)  
This means you don't start unbound with `unbound -v`, but use `sudo service unbound stop && sudo service unbound start` to get things running.

NOT sure this will help...

---

<div class="post-metadata">

**Author:** ![ChurchOfNoise](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/churchofnoise/32/17886_2.png) [@ChurchOfNoise](https://discourse.pi-hole.net/u/ChurchOfNoise)\
**Post date:** [August 10, 2020, 11:36am UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/41 "2020-08-10T11:36:50Z")

</div>

I have a similar issue: did a fresh install and have a similar issue when running sudo unbound -v:

> [1597059373] unbound[2177:0] notice: Start of unbound 1.11.1.  
> Aug 10 12:36:13 unbound[2177:0] error: can't bind socket: Address already in use for 127.0.0.1 port 8953  
> Aug 10 12:36:13 unbound[2177:0] error: cannot open control interface 127.0.0.1 8953  
> Aug 10 12:36:13 unbound[2177:0] fatal error: could not open ports

This is the output of  
`ps -aux | grep unbound`

> root 317 0.0 0.0 0 0 ? I 11:59 0:00 [kworker/u2:4-events\_unbound]  
> unbound 419 0.3 3.4 19000 15320 ? Ss 11:59 0:07 /usr/sbin/unbound -c /etc/unbound/unbound.conf -d  
> pi 2140 0.0 0.4 7332 2024 pts/0 S+ 12:33 0:00 grep --color=auto unbound

Any idea how I can solve this pls?  
(edit: running latest Pi-Hole master i.e. 5.1.2 and compiled Unbound from the Unbound Github i.e. 1.11.1)

---

<div class="post-metadata">

**Author:** ![ChurchOfNoise](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/churchofnoise/32/17886_2.png) [@ChurchOfNoise](https://discourse.pi-hole.net/u/ChurchOfNoise)\
**Post date:** [August 10, 2020, 4:21pm UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/43 "2020-08-10T16:21:34Z")

</div>

Result of

```auto
sudo netstat -tulpen | grep 8953

```

is

> tcp 0 0 127.0.0.1:8953 0.0.0.0:\* LISTEN 0 13951 419/unbound

And result of

```auto
sudo netstat -tulpen | grep 5335

```

is

> tcp 0 0 127.0.0.1:5335 0.0.0.0:\* LISTEN 0 13950 419/unbound  
> udp 0 0 127.0.0.1:5335 0.0.0.0:\* 0 13949 419/unbound

So, if I get it correctly, running unbound -v tries to start it. Then the message makes sense as it is indeed already running...

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [August 10, 2020, 4:23pm UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/44 "2020-08-10T16:23:00Z")

</div>

You are trying to start a running instance of unbound.

---

<div class="post-metadata">

**Author:** ![ChurchOfNoise](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/churchofnoise/32/17886_2.png) [@ChurchOfNoise](https://discourse.pi-hole.net/u/ChurchOfNoise)\
**Post date:** [August 10, 2020, 4:23pm UTC](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881/45 "2020-08-10T16:23:39Z")

</div>

Thanks - learnt something here today...

[Previous page](https://discourse.pi-hole.net/t/unbound-1-9-2-released-june-17/20881.md?page=1)
