Bind9 sends an OPT RR with the SOA query, related to XFR. OpenDNSSEC does not support EDNS and confuses the OPT RR with a bad TSIG RR, and sends back a FORMERR.
Solution: implement EDNS.
Bind9 sends an OPT RR with the SOA query, related to XFR. OpenDNSSEC does not support EDNS and confuses the OPT RR with a bad TSIG RR, and sends back a FORMERR.
Solution: implement EDNS.