Hello,
Very important change was in the package 'unbound' of the world DNSSEC.
The changing or "rolling" of the KSK Key was originally scheduled to occur on 11 October, but it is being delayed because some recently obtained data shows that a significant number of resolvers used by Internet Service Providers (ISPs) and Network Operators are not yet ready for the Key Rollover. The availability of this new data is due to a very recent DNS protocol feature that adds the ability for a resolver to report back to the root servers which keys it has configured.
https://www.icann.org/news/announcement-2017-09-27-en
Presentation: A Look at RFC 8145 Trust Anchor Signaling for the 2017 KSK Rollover
https://www.icann.org/en/system/fil...-anchor-signaling-ksk-rollover-11oct17-en.pdf
Option 'trust-anchor-signaling' of unbound was enabled by default from version 1.6.7 at 10 October 2017. FreeBSD port 'unbound' have this version now. But FreeBSD 11.1-p1 have version 1.5.10 that have not this option:
=========================================
/usr/sbin/unbound-control get_option trust-anchor-signaling
error unknown option
=========================================
Please, update unbound dns resolver (local_unbound) in the system FreeBSD.
Very important change was in the package 'unbound' of the world DNSSEC.
The changing or "rolling" of the KSK Key was originally scheduled to occur on 11 October, but it is being delayed because some recently obtained data shows that a significant number of resolvers used by Internet Service Providers (ISPs) and Network Operators are not yet ready for the Key Rollover. The availability of this new data is due to a very recent DNS protocol feature that adds the ability for a resolver to report back to the root servers which keys it has configured.
https://www.icann.org/news/announcement-2017-09-27-en
Presentation: A Look at RFC 8145 Trust Anchor Signaling for the 2017 KSK Rollover
https://www.icann.org/en/system/fil...-anchor-signaling-ksk-rollover-11oct17-en.pdf
Option 'trust-anchor-signaling' of unbound was enabled by default from version 1.6.7 at 10 October 2017. FreeBSD port 'unbound' have this version now. But FreeBSD 11.1-p1 have version 1.5.10 that have not this option:
=========================================
/usr/sbin/unbound-control get_option trust-anchor-signaling
error unknown option
=========================================
Please, update unbound dns resolver (local_unbound) in the system FreeBSD.