# Can not get bind to resolve DNSSEC domains when DNSSEC is set to yes or auto

**URL:** <https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860>\
**Category:** Rocky Linux Help & Support\
**Tags:** rocky-linux-9\
**Created:** [March 11, 2025, 10:23pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860 "2025-03-11T22:23:23Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![John316](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/john316/32/4991_2.png) [@John316](https://forums.rockylinux.org/u/John316)\
**Post date:** [March 11, 2025, 10:23pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/1 "2025-03-11T22:23:23Z")

</div>

I’m on Rocky 9.5. bind-chroot 32:9.16.23-24.el9\_5.3

I am not trying to sign a zone. I am just trying to get the resolver to work using DNSSEC.

I have read docs for bind, bind-dnssec, searched for how tos, read setup instructions from several different sites and still cannot get bind to resolve hosts or domains when dnssec-validation is set to yes or auto. With it set to auto or yes, the resolver does not return an address.

When I set dnssec-validation to no, then the domains the have DNSSEC registered resolve and provide an IP address.

Looking for some insight on what options to put in named.conf and anything else needed in order to get DNSSEC working in the bind resolver.

I would prefer to use “auto,” so it is more maintenance free, but “yes” is preferable to “no” which is what I have to use presently.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [March 12, 2025, 7:56am UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/2 "2025-03-12T07:56:04Z")

</div>

From this link: [https://kb.isc.org/docs/aa-01182](https://kb.isc.org/docs/aa-01182)

Do you have the managed-keys entries that are mentioned? These exist on my Debian installations, and when I set it to auto I can still use DNS, and even make DNSSEC queries. That’s about the only thing I can think of, since nothing else was changed in bind configuration.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [March 12, 2025, 8:55am UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/3 "2025-03-12T08:55:52Z")

</div>

On my Rocky 9 I just installed the bind and bind-dnssec-utils packages, then checked /etc/named.conf to see if dnssec-validation was changed from yes to auto, and then started the service. I could make DNS queries without problem, and also verify dnssec using something like below:

```auto
dig @localhost com. SOA +dnssec

```

and verifying the files I mentioned:

```auto
root@rocky9:~# ls -lha /var/named/dynamic/
total 8.0K
drwxrwx---. 2 named named 60 Mar 12 09:54 .
drwxrwx--T. 5 root named 127 Mar 12 09:52 ..
-rw-r--r--. 1 named named 1.4K Mar 12 09:54 managed-keys.bind
-rw-r--r--. 1 named named 1.4K Mar 12 09:53 managed-keys.bind.jnl

```

for your chroot environment it will be similar, but you’ll need to make sure that the chroot has access to those managed-keys files.

---

<div class="post-metadata">

**Author:** ![John316](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/john316/32/4991_2.png) [@John316](https://forums.rockylinux.org/u/John316)\
**Post date:** [March 12, 2025, 3:14pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/4 "2025-03-12T15:14:30Z")

</div>

I need to clarify.

It is not that it won’t resolve any hosts when it is set to auto. It is it won’t resolve any hosts or domains that are DNSSEC signed.

[comcast.net](http://comcast.net) is DNSSEC signed.

This is the results of dog when set to auto:

```auto
dig @192.168.1.5 +dnssec +multiline comcast.net

; <<>> DiG 9.16.23-RH <<>> @192.168.1.5 +dnssec +multiline comcast.net
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 31817
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 1232
; COOKIE: 67080a0d9751c94e0100000067d19e6a9641015b4caec558 (good)
;; QUESTION SECTION:
;comcast.net. IN A

;; Query time: 267 msec
;; SERVER: 192.168.1.5#53(192.168.1.5)
;; WHEN: Wed Mar 12 10:47:06 EDT 2025
;; MSG SIZE rcvd: 68

```

This is the output of dig when it is set to no:

```auto
dig @192.168.1.5 +dnssec +multiline comcast.net

; <<>> DiG 9.16.23-RH <<>> @192.168.1.5 +dnssec +multiline comcast.net
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34559
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 1232
; COOKIE: eeb3aa4944a6b9ca0100000067d19f1783add808651449e5 (good)
;; QUESTION SECTION:
;comcast.net. IN A

;; ANSWER SECTION:
comcast.net. 7200 IN A 96.99.227.0
comcast.net. 7200 IN RRSIG A 5 2 7200 (
                                20250321144439 20250304143939 26550 comcast.net.
                                ko1btIlVgI8syUael9yZx3BeJE7QOcDgBruI3hqrrox4
                                LMnyondSbTkO6yQj/LnKDKtqstR1Q9BTOwWcvLX7TFW9
                                4ZIluBFfZeQjnvXTkIh2yTGkUNrVo/zjODI/MNXKxTsN
                                SE/miWIGlrelsjEtH2QNtZzPzw7kUQ1xenLgobQ= )

;; Query time: 302 msec
;; SERVER: 192.168.1.5#53(192.168.1.5)
;; WHEN: Wed Mar 12 10:49:59 EDT 2025
;; MSG SIZE rcvd: 255

```

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [March 12, 2025, 3:46pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/5 "2025-03-12T15:46:12Z")

</div>

I still think your configuration is wrong. As I said before, check your config. I’ve just done this on mine that I installed this morning when attempting to help you, and it works:

```auto
root@rocky9:~# dig @localhost comcast.net +dnssec

; <<>> DiG 9.16.23-RH <<>> @localhost comcast.net +dnssec
; (2 servers found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 44953
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 1232
; COOKIE: 2d0db96cd68fe4a10100000067d1ac2a088b491211d5e6ef (good)
;; QUESTION SECTION:
;comcast.net. IN	A

;; ANSWER SECTION:
comcast.net. 7136	IN	A	96.99.227.0
comcast.net. 7136	IN	RRSIG	A 5 2 7200 20250321144439 20250304143939 26550 comcast.net. ko1btIlVgI8syUael9yZx3BeJE7QOcDgBruI3hqrrox4LMnyondSbTkO 6yQj/LnKDKtqstR1Q9BTOwWcvLX7TFW94ZIluBFfZeQjnvXTkIh2yTGk UNrVo/zjODI/MNXKxTsNSE/miWIGlrelsjEtH2QNtZzPzw7kUQ1xenLg obQ=

```

please use the formatting tools when posting like I’ve done here, it makes posts easier to read. I’ve just edited your post above to format it correctly.

---

<div class="post-metadata">

**Author:** ![John316](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/john316/32/4991_2.png) [@John316](https://forums.rockylinux.org/u/John316)\
**Post date:** [March 12, 2025, 5:22pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/6 "2025-03-12T17:22:01Z")

</div>

Are you running as caching using forwarding?

I am configured as authoritative for my internal zones using root hints.

I was using this same conf under Fedora without an issue.

I used named-checkconf and it didn’t find any errors, but it doesn’t check semantics.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [March 12, 2025, 5:39pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/7 "2025-03-12T17:39:21Z")

</div>

I just configured a zone file without dnssec, and I am still able to make internal and external (forwarded) queries. My internal DNS resolves and I can still resolve comcast with dnssec entries.

You will have to show all your configuration and file locations for anyone to help further, but it would suggest whatever configuration you are using is incorrect. Fedora is not Rocky, so you cannot just copy/paste configuration from one machine to another.

---

<div class="post-metadata">

**Author:** ![John316](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/john316/32/4991_2.png) [@John316](https://forums.rockylinux.org/u/John316)\
**Post date:** [March 12, 2025, 6:57pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/10 "2025-03-12T18:57:11Z")

</div>

Sorry about the formatting. I was posting from my phone.

I will post conf file and directory structure. I noticed what I posted also suffered from formatting issues.

---

<div class="post-metadata">

**Author:** ![John316](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/john316/32/4991_2.png) [@John316](https://forums.rockylinux.org/u/John316)\
**Post date:** [March 13, 2025, 1:52am UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/11 "2025-03-13T01:52:43Z")

</div>

Here is the output of named-checkconf -p .

```auto
 controls {
        inet 127.0.0.1 allow {
                "localhost";
        } keys {
                "rndc-key";
        };
};
options {
        directory "/var/named";
        dump-file "/var/named/data/cache_dump.db";
        geoip-directory "/usr/share/GeoIP";
        listen-on-v6 port 53 {
                "any";
        };
        managed-keys-directory "/var/named/dynamic";
        memstatistics-file "/var/named/data/named_mem_stats.txt";
        pid-file "/run/named/named.pid";
        session-keyfile "/run/named/session.key";
        statistics-file "/var/named/data/named_stats.txt";
        dnssec-validation no;
        allow-query {
                "any";
        };
        notify no;
};
key "rndc-key" {
        algorithm "hmac-sha256";
        secret "<redacted>";
};
trust-anchors {
        "." initial-ds 20326 8 2 "E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D";
};
zone "." IN {
        type hint;
        file "named.ca";
};
zone "localhost.localdomain" IN {
        type master;
        file "named.localhost";
        allow-update {
                "none";
        };
};
zone "localhost" IN {
        type master;
        file "named.localhost";
        allow-update {
                "none";
        };
};
zone "1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa" IN {
        type master;
        file "named.loopback";
        allow-update {
                "none";
        };
};
zone "1.0.0.127.in-addr.arpa" IN {
        type master;
        file "named.loopback";
        allow-update {
                "none";
        };
};
zone "0.in-addr.arpa" IN {
        type master;
        file "named.empty";
        allow-update {
                "none";
        };
};
zone "internal.grifent.com" {
        type master;
        file "master/db.internal.grifent.com";
        allow-update {
                "none";
        };
};
zone "1.168.192.in-addr.arpa" {
        type master;
        file "master/db.192.168.1";
        allow-update {
                "none";
        };
};
zone "15.168.192.in-addr.arpa" {
        type master;
        file "master/db.192.168.15";
        allow-update {
                "none";
        };
};
zone "0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.IP6.ARPA" {
        type master;
        file "master/db.fe80::";
        allow-update {
                "none";
        };
};

```

Here is the chroot tree.

```auto

├── [drwxr-x--- root named] dev
│ ├── [crw-rw-r-- root named] null
│ ├── [crw-rw-r-- root named] random
│ ├── [crw-rw-r-- root named] urandom
│ └── [crw-rw-r-- root named] zero
├── [drwxr-x--- root named] etc
│ ├── [drwxr-x--- root named] crypto-policies
│ │ └── [drwxr-x--- root named] back-ends
│ │ └── [-rw-r--r-- root root] bind.config
│ ├── [-rw-r--r-- root root] localtime
│ ├── [drwxr-x--- root named] named
│ │ ├── [-rw-r--r-- root named] named.dynamic.zones
│ │ ├── [-rw-r--r-- root named] named.forwarding.zones
│ │ ├── [-rw-r----- root named] named.master.zones
│ │ └── [-rw-r----- root named] named.slave.zones
│ ├── [-rw-r--r-- root root] named.conf
│ ├── [-rw-r----- root named] named.rfc1912.zones
│ ├── [-rw-r--r-- root named] named.root.key
│ ├── [drwxr-x--- root named] pki
│ │ └── [drwxr-x--- root named] dnssec-keys
│ ├── [-rw-r--r-- root root] protocols
│ ├── [-rw-r----- root named] rndc.key
│ └── [-rw-r--r-- root root] services
├── [drwxr-xr-x root root] proc
│ └── [drwxr-xr-x root root] sys
│ └── [drwxr-xr-x root root] net
│ └── [drwxr-xr-x root root] ipv4
│ └── [-rw-r--r-- root root] ip_local_port_range
├── [drwxr-x--- root named] run
│ └── [drwxr-xr-x named named] named
│ ├── [-rw-r--r-- named named] named.pid
│ └── [-rw------- named named] session.key
├── [drwxr-xr-x root root] usr
│ ├── [drwxr-xr-x root root] lib64
│ │ ├── [drwxr-xr-x root root] bind
│ │ └── [drwxr-xr-x root root] named
│ │ └── [-rwxr-xr-x root root] filter-aaaa.so
│ └── [drwxr-xr-x root root] share
│ └── [drwxr-xr-x root root] GeoIP
│ ├── [-rw-r--r-- root root] GeoLite2-City.mmdb
│ └── [-rw-r--r-- root root] GeoLite2-Country.mmdb
└── [drwxr-x--- root named] var
    ├── [drwxrwx--- named named] log
    ├── [drwxrwx--- root named] named
    │ ├── [drwxr-x--- root named] chroot
    │ │ ├── [drwxr-x--- root named] dev
    │ │ │ ├── [crw-rw-r-- root named] null
    │ │ │ ├── [crw-rw-r-- root named] random
    │ │ │ ├── [crw-rw-r-- root named] urandom
    │ │ │ └── [crw-rw-r-- root named] zero
    │ │ ├── [drwxr-x--- root named] etc
    │ │ │ ├── [drwxr-x--- root named] crypto-policies
    │ │ │ │ └── [drwxr-x--- root named] back-ends
    │ │ │ │ └── [-rw-r--r-- root root] bind.config
    │ │ │ ├── [-rw-r--r-- root root] localtime
    │ │ │ ├── [drwxr-x--- root named] named
    │ │ │ ├── [-rw-r--r-- root root] named.conf
    │ │ │ ├── [-rw-r--r-- root root] named.rfc1912.zones
    │ │ │ ├── [-rw-r--r-- root root] named.root.key
    │ │ │ ├── [drwxr-x--- root named] pki
    │ │ │ │ └── [drwxr-x--- root named] dnssec-keys
    │ │ │ ├── [-rw-r--r-- root root] protocols
    │ │ │ ├── [-rw-r--r-- root root] rndc.key
    │ │ │ └── [-rw-r--r-- root root] services
    │ │ ├── [drwxr-xr-x root root] proc
    │ │ │ └── [drwxr-xr-x root root] sys
    │ │ │ └── [drwxr-xr-x root root] net
    │ │ │ └── [drwxr-xr-x root root] ipv4
    │ │ │ └── [-rw-r--r-- root root] ip_local_port_range
    │ │ ├── [drwxr-x--- root named] run
    │ │ │ └── [drwxr-xr-x named named] named
    │ │ ├── [drwxr-xr-x root root] usr
    │ │ │ ├── [drwxr-xr-x root root] lib64
    │ │ │ │ ├── [drwxr-xr-x root root] bind
    │ │ │ │ └── [drwxr-xr-x root root] named
    │ │ │ └── [drwxr-xr-x root root] share
    │ │ │ └── [drwxr-xr-x root root] GeoIP
    │ │ └── [drwxr-x--- root named] var
    │ │ ├── [drwxrwx--- named named] log
    │ │ ├── [drwxrwx--T root named] named
    │ │ ├── [lrwxrwxrwx named named] run -> ../run
    │ │ └── [drwxrwx--- named named] tmp
    │ ├── [drwxrwx--- named named] data
    │ │ ├── [-rw-r--r-- named named] named.run
    │ │ ├── [-rw-r--r-- named named] named.run-20250216
    │ │ ├── [-rw-r--r-- named named] named.run-20250223
    │ │ ├── [-rw-r--r-- named named] named.run-20250302
    │ │ └── [-rw-r--r-- named named] named.run-20250309
    │ ├── [drwxrwx--- named named] dynamic
    │ │ ├── [-rw-r--r-- named named] managed-keys.bind
    │ │ └── [-rw-r--r-- named named] managed-keys.bind.jnl
    │ ├── [drwxrwx--- named named] master
    │ │ ├── [-rw-rw---- named named] db.192.168.1
    │ │ ├── [-rw-rw---- named named] db.192.168.15
    │ │ ├── [-rw-rw---- named named] db.fe80::
    │ │ ├── [-rw-rw---- named named] db.internal.grifent.com
    │ │ └── [-rw-rw---- named named] internal.grifent.soa
    │ ├── [-rw-r----- root named] named.ca
    │ ├── [-rw-r----- root named] named.empty
    │ ├── [-rw-r----- root named] named.localhost
    │ ├── [-rw-r----- root named] named.loopback
    │ └── [drwxrwx--- named named] slaves
    ├── [lrwxrwxrwx named named] run -> ../run
    └── [drwxrwx--- named named] tmp

53 directories, 51 files

```

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [March 13, 2025, 7:17am UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/12 "2025-03-13T07:17:40Z")

</div>

Can you also add this to `named.conf` so that we can enable/disable debugging:

```auto
logging {
        channel default_debug {
                file "data/named.run" size 10m;
                severity dynamic;
                /*severity debug 3;*/
                print-time yes;
                print-severity yes;
                print-category yes;
        };
        category default { default_debug; };
};

```

then to enable debug do this:

```auto
rndc trace 3

```

and then try to make some DNS queries normal and dnssec ones. To disable debugging afterwards do:

```auto
rndc notrace

```

check log files as well for potential hints on where problems might be when you make a query. If you leave the named.conf stuff relating to debugging, you can enable/disable debug just using the trace/notrace commands given. Later on you may remove from named.conf once the problem is resolved.

---

<div class="post-metadata">

**Author:** ![John316](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/john316/32/4991_2.png) [@John316](https://forums.rockylinux.org/u/John316)\
**Post date:** [March 13, 2025, 3:21pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/13 "2025-03-13T15:21:44Z")

</div>

Looks like the resolver is trying to use IPv6 to validate the DNSSEC query.

My ISP doesn’t support IPv6 yet.

I use IPv6 on my internal (non public) domain.

I don’t know how to make the resolver use IPv4 for external queries.

The web searches say to disable IPv6 in Network Manager. If that is the solution, I’ll have to remove IPv6 use internally.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [March 13, 2025, 3:24pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/14 "2025-03-13T15:24:01Z")

</div>

> [@John316](#):
>
> ```auto
> listen-on-v6 port 53 {
> "any";
> };
> 
> ```

Probably better to listen only on ipv4 not on ipv6. You can do this:

```auto
listen-on-v6 { none; };

```

and for listening on ipv4:

```auto
listen-on port 53 { 127.0.0.1; };

```

change 127.0.0.1 to the IP of your machine so that other hosts can query it or just change it to any:

```auto
listen-on port 53 { any; };

```

but then obviously that means you’re not going to be able to use ipv6 addresses internally. Seems strange though if you change it to no, that it suddenly starts resolving even for ipv6. I don’t use ipv6 and don’t plan on using it internally anyway. Both my LAN and WAN/Internet is ipv4.

---

<div class="post-metadata">

**Author:** ![John316](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/john316/32/4991_2.png) [@John316](https://forums.rockylinux.org/u/John316)\
**Post date:** [March 13, 2025, 3:33pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/15 "2025-03-13T15:33:23Z")

</div>

I can do that. Of course then I will have to disable IPv6 on my internal hosts.

Choice: get DNSSEC working and lose IPv6  
or keep IPv6 and disable DNSSEC.

Thank you for your help @iwalker .

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [March 13, 2025, 3:40pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/16 "2025-03-13T15:40:31Z")

</div>

I have the reverse to be honest. If I just do a standard dig command then it will give me ipv4 as you saw from the comcast output before. Now if I do:

```auto
dig aaaa comcast.net

```

it should reply with ipv6 but doesn’t. Most likely because I’m using ipv4, even though I did a query to ipv6 localhost `::1`.

Or at least for comcast I do. For google, it will reply with the ipv6 DNS entry. It would suggest that Comcast DNS servers see me coming from a public ipv4 address and only replies with ipv4 entries and not ipv6. Yet, google replies even if I do `dig aaaa` or `dig a`.

---

<div class="post-metadata">

**Author:** ![John316](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/john316/32/4991_2.png) [@John316](https://forums.rockylinux.org/u/John316)\
**Post date:** [March 13, 2025, 4:38pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/17 "2025-03-13T16:38:54Z")

</div>

Just changing

listen-on-v6 { none; };

didn’t solve the issue.

I guess something in the resolver sees my server has an IPv6 address and makes an assumption that the query to the root servers should be done using IPv6. Each root is tried at the IPv6 address but no IPv4 address is ever tried.

There ought to be a way to configure bind to use IPv4 (or 6 or either) for query transport.

---

<div class="post-metadata">

**Author:** ![John316](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/john316/32/4991_2.png) [@John316](https://forums.rockylinux.org/u/John316)\
**Post date:** [March 13, 2025, 5:09pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/18 "2025-03-13T17:09:11Z")

</div>

I found this:

…

Can’t remember where I found this solution, but here it is

In /etc/bind/named.conf.local:

// disable lookup over IPv6  
server ::/0 {  
bogus yes;  
};

It then pretends that IP addresses in the IPv6 range are non reachable and does it with IPv4 instead.  
…  
at [Configure BIND to prefer IPv4 without disabling IPv6 - Server Fault](https://serverfault.com/questions/841419/configure-bind-to-prefer-ipv4-without-disabling-ipv6)

Then for the internal server IPv6 address  
should be able to have more specific server blocks with bogus no for your internal servers.

What do you think @iwalker ?

---

<div class="post-metadata">

**Author:** ![John316](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/john316/32/4991_2.png) [@John316](https://forums.rockylinux.org/u/John316)\
**Post date:** [March 13, 2025, 5:23pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/19 "2025-03-13T17:23:29Z")

</div>

Tried it.

Didn’t work.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [March 13, 2025, 6:36pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/20 "2025-03-13T18:36:11Z")

</div>

I don’t have either of those options, but my bind listens on localhost ipv4 and ipv6 and does resolve each entry. You can put both options on any like I have. Unfortunately, I don’t use ipv6 so am unable to help any further. I can post my config for you, but it’s not a chroot config, just basic bind server, but should still work irrespective of whether it’s normal named or chrooted.

---

<div class="post-metadata">

**Author:** ![John316](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/john316/32/4991_2.png) [@John316](https://forums.rockylinux.org/u/John316)\
**Post date:** [March 13, 2025, 6:36pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/21 "2025-03-13T18:36:52Z")

</div>

Just tried  
…  
blackhole {  
::/0;  
};  
…

That didn’t work either.

Next. - disable IPv6 zones and addresses.

Sigh

From what I seen in searching, I’m not the only one that wants to do this. Bind just can’t handle it.

Actually, newer version of bind probably does because I truly believe this configuration was working on Fedora 40.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [March 13, 2025, 6:37pm UTC](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860/22 "2025-03-13T18:37:39Z")

</div>

My config, which is pretty vanilla:

```auto
root@rocky9:~# named-checkconf -p
logging {
	channel "default_debug" {
		file "data/named.run";
		severity dynamic;
	};
};
options {
	directory "/var/named";
	dump-file "/var/named/data/cache_dump.db";
	geoip-directory "/usr/share/GeoIP";
	listen-on port 53 {
		127.0.0.1/32;
	};
	listen-on-v6 port 53 {
		::1/128;
	};
	managed-keys-directory "/var/named/dynamic";
	memstatistics-file "/var/named/data/named_mem_stats.txt";
	pid-file "/run/named/named.pid";
	recursing-file "/var/named/data/named.recursing";
	secroots-file "/var/named/data/named.secroots";
	session-keyfile "/run/named/session.key";
	statistics-file "/var/named/data/named_stats.txt";
	disable-algorithms "." {
		"RSAMD5";
		"RSASHA1";
		"NSEC3RSASHA1";
		"DSA";
		"NSEC3DSA";
		"ED25519";
		"ED448";
		"ECCGOST";
	};
	disable-ds-digests "." {
		"SHA-1";
		"GOST";
	};
	dnssec-validation yes;
	recursion yes;
	allow-query {
		"localhost";
	};
};
trust-anchors {
	"." initial-ds 20326 8 2 "E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D";
};
zone "." IN {
	type hint;
	file "named.ca";
};
zone "myzone.com" IN {
	type master;
	file "/var/named/myzone.com.zone";
};
zone "localhost.localdomain" IN {
	type master;
	file "named.localhost";
	allow-update {
		"none";
	};
};
zone "localhost" IN {
	type master;
	file "named.localhost";
	allow-update {
		"none";
	};
};
zone "1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa" IN {
	type master;
	file "named.loopback";
	allow-update {
		"none";
	};
};
zone "1.0.0.127.in-addr.arpa" IN {
	type master;
	file "named.loopback";
	allow-update {
		"none";
	};
};
zone "0.in-addr.arpa" IN {
	type master;
	file "named.empty";
	allow-update {
		"none";
	};
};

```

[Next page](https://forums.rockylinux.org/t/can-not-get-bind-to-resolve-dnssec-domains-when-dnssec-is-set-to-yes-or-auto/17860.md?page=2)
