2011/8/25 Paul Wouters <paul@xxxxxxxxxxxxx>: > Again, this is based on f14, not f15/f16. I am not sure how much this has been > addressed. But if we want DNSSEC validation on the endnode, at the very least > 127.0.0.1:53 needs to be left free. Are you sure the dnsmasq instance started by libvirt is really grabbing 127.0.0.1:53? In my experiments it did not, and the issue instead was that the other DNS server [1] wanted to grab port 53 on *all* interfaces. - Thomas [1] In my case that was a second instance of dnsmasq, and I had to set --interface=lo and --bind-interfaces. -- Thomas Moschny <thomas.moschny@xxxxxxxxx> -- devel mailing list devel@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/devel