// validating resolver options { {% include_indented "_common/options.conf.j2" %} dnssec-validation yes; minimal-responses no; // Keep the DS insecurity proof deterministic: without this, a cached // NSEC from an earlier forgery lets aggressive-NSEC synthesis answer the // grandchild query before the DS fetch that drives is_insecure_referral(). synth-from-dnssec no; // Pinned so the RRSIG-count cap in is_insecure_referral() is tested // against a known number rather than the built-in default. max-validations-per-fetch @MAX_VALIDATIONS@; }; {% include "_common/controls.conf.j2" %} {% include "_common/root.hint.conf" %} zone "p031.test" { type static-stub; server-addresses { 10.53.0.1; }; }; trust-anchors { p031.test. static-key 257 3 13 "@PARENT_DNSKEY@"; };