validate: various failures on 1.2.6 not related to forwarding
This seems independent of forwarding mode, and it fails on 1.2.6 as well. Example log:
[37659][plan] plan 'v1.pcextreme.nl.' type 'DNSKEY'
[60204][iter] 'v1.pcextreme.nl.' type 'DNSKEY' id was assigned, parent id 37659
[60204][resl] => querying: '93.180.70.53' score: 10 zone cut: 'v1.pcextreme.nl.' m12n: 'v1.PcExtrEME.nL.' type: 'DNSKEY' proto: 'udp'
[60204][iter] <= rcode: NOERROR
[60204][vldr] <= bad keys, broken trust chain
Other resolvers find the domain OK, including dnsviz, unbound and google.
EDIT: this particular name requires GOST for DS, and it's now correctly downgraded to insecure since !333 (merged) (and thus v1.3.2).
Edited by Vladimír Čunát