Commit dabc9aa0bd for bind
commit dabc9aa0bde9d0d7dd8ce67d418647c383420e5a
Author: Jan-Piet Mens <jp@mens.de>
Date: Sun Oct 4 07:13:14 2026 +0200
Note for checkds that dnssec-validation is required
I configured `dnssec-validation no` in named.conf on an authoritative server because I didn't think I'd need validation, and it avoids a `managed-keys` database on disk, which an auth server won't need, right?!
A few hours later, I experimented with `parental-agent` and `checkds`, setting the latter first to `explicit` and then to `yes`, but I couldn't get past this diagnostic:
```
Invalid NS RRset for 'example' trust level 7
```
After looking at the BIND's source and finding a test case which uses trust anchors. While typing `trust-anchors {}` into `named.conf`, the penny/cent/rupee/lira dropped: re-enabling `dnssec-validation auto` got the cogs oiled.
I feel this should be added as a note to the ARM in the section with checkds reference, particularly as the reference for dnssec-validation doesn't mention checkds
diff --git a/doc/arm/reference.rst b/doc/arm/reference.rst
index a005163e05..d5eb06943d 100644
--- a/doc/arm/reference.rst
+++ b/doc/arm/reference.rst
@@ -6703,6 +6703,9 @@ The following options apply to DS queries sent to :any:`parental-agents`:
:option:`rndc dnssec -checkds <rndc dnssec>` with the appropriate parameters,
to signal that specific DS records are published and/or withdrawn.
+ Responses to DS queries are validated, so :any:`dnssec-validation` must be
+ enabled for the server.
+
.. namedconf:statement:: parental-source
:tags: dnssec
:short: Specifies which local IPv4 source address is used to send parental DS queries.