On 07/10/2026 15.09, Stephane Bortzmeyer wrote:
If Knot Resolver has no directive about trust anchors, it stills works
and validates automatically, great.

Now, I wanted to check the trust anchors in preparation for sunday's
rollover and I have questions:

* when you do not specify a trust anchors file, where is it stored?
I've checked many places on the disk without a result. (More general
question: how to display the entire configuration, with the default values?)

The default trust anchors are configurable during build time, and so far they are not represented explicitly in the configuration model (which just shows None).

It's certainly possible to dive a little into internals, e.g. run

echo 'trust_anchors.summary()' | sudo socat - /run/knot-resolver/control/0
# or more detailed
echo 'trust_anchors' | sudo socat - /run/knot-resolver/control/0


We prefer to use an in-distro package with this information, e.g. dns-root-data in .deb distros: https://packages.debian.org/trixie/dns-root-data but the builder/packager has other options: install our own file with those TAs (we upgraded those in June 2024 already) or use a bootstrapping method (or any path in the filesystem).


* when you do not specify a trust anchors file, how to check that you
indeed got the new root key?

Generally I think it's best to test from outside of the resolver, e.g. https://dnstest.dev/ksk-2024/


% knot-resolver --version
6.4.0

That's slightly outdated, but not significantly in this context - unless you use trust anchor bootstrapping (but that isn't a common config, I think), as 6.4.1 added https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1847