diff --git a/etc/unbound/unbound.conf.d/root-auto-trust-anchor-file.conf b/etc/unbound/unbound.conf.d/root-auto-trust-anchor-file.conf new file mode 100644 index 00000000..48f635b1 --- /dev/null +++ b/etc/unbound/unbound.conf.d/root-auto-trust-anchor-file.conf @@ -0,0 +1,6 @@ +# This is another Debian default, that I may be missing under Arch, even +# if the location changes. +server: + # The following line will configure unbound to perform cryptographic + # DNSSEC validation using the root trust anchor. + auto-trust-anchor-file: "/var/lib/unbound/root.key"