diff --git a/src/etc/mtree/4.4BSD.dist b/src/etc/mtree/4.4BSD.dist index 77985853..2c92afb5 100644 --- a/src/etc/mtree/4.4BSD.dist +++ b/src/etc/mtree/4.4BSD.dist @@ -1,4 +1,4 @@ -# $OpenBSD: 4.4BSD.dist,v 1.244 2014/03/18 22:36:29 miod Exp $ +# $OpenBSD: 4.4BSD.dist,v 1.245 2014/03/21 00:23:15 sthen Exp $ /set type=dir uname=root gname=wheel mode=0755 # . @@ -1362,6 +1362,11 @@ etc uname=root gname=wheel mode=0755 # ./var/unbound/etc .. +# ./var/unbound/db +db uname=root gname=_unbound mode=0775 +# ./var/unbound/db +.. + # ./var/unbound .. diff --git a/src/etc/unbound.conf b/src/etc/unbound.conf index 4e0e8148..ecb1fd1f 100644 --- a/src/etc/unbound.conf +++ b/src/etc/unbound.conf @@ -1,4 +1,4 @@ -# $OpenBSD: unbound.conf,v 1.1 2014/03/15 00:34:18 sthen Exp $ +# $OpenBSD: unbound.conf,v 1.2 2014/03/21 00:23:15 sthen Exp $ server: interface: 127.0.0.1 @@ -14,10 +14,10 @@ server: hide-identity: yes hide-version: yes - # Enable DNSSEC validation. Fetch a root key with unbound-anchor(8). + # Uncomment to enable DNSSEC validation. # #module-config: "validator iterator" - #auto-trust-anchor-file: "/var/unbound/etc/root.key" + #auto-trust-anchor-file: "/var/unbound/db/root.key" # Serve zones authoritatively from Unbound to resolver clients. # Not for external service. Note use of "nodefault" for AS112 zones,