diff -upr unbound-1.5.6.orig/doc/example.conf.in unbound-1.5.6/doc/example.conf.in --- unbound-1.5.6.orig/doc/example.conf.in 2015-11-16 14:42:32.068772139 +0100 +++ unbound-1.5.6/doc/example.conf.in 2015-11-16 14:42:55.639731588 +0100 @@ -212,7 +212,7 @@ server: # How to do this is specific to your OS. # # If you give "" no chroot is performed. The path must not end in a /. - # chroot: "@UNBOUND_CHROOT_DIR@" + chroot: "" # if given, user privileges are dropped (after binding port), # and the given username is assumed. Default is user "unbound". @@ -243,7 +243,7 @@ server: # file to read root hints from. # get one from ftp://FTP.INTERNIC.NET/domain/named.cache - # root-hints: "" + root-hints: /etc/unbound/root.hints # enable to not answer id.server and hostname.bind queries. # hide-identity: no @@ -361,7 +361,7 @@ server: # you start unbound (i.e. in the system boot scripts). And enable: # Please note usage of unbound-anchor root anchor is at your own risk # and under the terms of our LICENSE (see that file in the source). - # auto-trust-anchor-file: "@UNBOUND_ROOTKEY_FILE@" + # auto-trust-anchor-file: "" # File with DLV trusted keys. Same format as trust-anchor-file. # There can be only one DLV configured, it is trusted from root down. @@ -372,7 +372,7 @@ server: # with several entries, one file per entry. # Zone file format, with DS and DNSKEY entries. # Note this gets out of date, use auto-trust-anchor-file please. - # trust-anchor-file: "" + trust-anchor-file: "@UNBOUND_ROOTKEY_FILE@" # Trusted key for validation. DS or DNSKEY. specify the RR on a # single line, surrounded by "". TTL is ignored. class is IN default.