On Fri, Mar 21, 2014 at 01:41:37PM +0000, Stuart Henderson wrote: > > Kind-of; things will work properly if the validator is enabled now, and it's > less bad than having /var/unbound/etc writable, but would really prefer to not > have anything at all in the chroot be writable by the unprivileged _unbound > user. Privilege separation would be desirable for this. >
Just out of curiosity: how come the shipped unbound.conf file mentions the "module-config:" setting? It appears to me that "validator iterator" is the default, or am i missing something? Regards, Patrik Lundin