My DNS server keeps complaining similar to this:
I had updated my system using ntpdate. But bind9 error logs didn't change.
After taking few times tinkering about his weird problem, I was stumbled upon a mailing list discussion about dnssec. It was an old discussion. There was a bug in the bind version (then) which produced similar error output if configured as forwarder.
I immediately changed my named.conf.options, from the following:
to this one:
finally, business went normal again!
I haven't dug deep about this issue. Once I figure out the problem, I'll update this post.
error (broken trust chain) resolving '0.ubuntu.pool.ntp.org/AAAA/IN': 208.67.220.220#53Having researched on Google, many people suggested that the problem lies on the time accuracy. Therefore, we need to update the clock.
I had updated my system using ntpdate. But bind9 error logs didn't change.
After taking few times tinkering about his weird problem, I was stumbled upon a mailing list discussion about dnssec. It was an old discussion. There was a bug in the bind version (then) which produced similar error output if configured as forwarder.
I immediately changed my named.conf.options, from the following:
dnssec-enable yes;
dnssec-validation yes;
dnssec-lookaside auto;
to this one:
dnssec-enable no;
dnssec-validation no;
after I restarted the bind9 service (I am using Ubuntu 12.04):
service bind9 restart
finally, business went normal again!
I haven't dug deep about this issue. Once I figure out the problem, I'll update this post.