domain-insecure should appear in a server clause.
[openresolv] / unbound.in
index 124cecf624edba1c426ded73851dde7421d5a085..a803615783fc9627036c1b05fc2a331faf66dd7e 100644 (file)
@@ -1,5 +1,5 @@
 #!/bin/sh
-# Copyright (c) 2009-2011 Roy Marples
+# Copyright (c) 2009-2014 Roy Marples
 # All rights reserved
 
 # unbound subscriber for resolvconf
@@ -45,7 +45,8 @@ for d in $DOMAINS; do
        ns="${d#*:}"
        case "$unbound_insecure" in
        [Yy][Ee][Ss]|[Tt][Rr][Uu][Ee]|[Oo][Nn]|1)
-               newconf="$newconf${NL}domain-insecure: \"$dn\""
+               newconf="$newconf${NL}server:$NL"
+               newconf="$newconf       domain-insecure: \"$dn\"$NL"
                ;;
        esac
        newconf="$newconf${NL}forward-zone:$NL  name: \"$dn\"$NL"