Hello, On Fri, Nov 26, 2010 at 1:48 PM, <lst_hoe02 at kwsoft.de> wrote: > This is a non default and labeled as experimental in the docu. It works fine > here with the default (no), maybe try to set it back to the default. > You could also try "+cdflag" to see if the non-result is related to DNSSEC. Yes indeed, works when using this. When you say this is a non default, which setting are you referring to? > BTW: Why do you not use the "auto-trust-anchor-file" setting as the > root-zone is now signed? Because at the time we implemented the setup, it wasn't :) This is now done. Thanks for the prompt response, appreciated! Cheers, Steph