This is a feature request. Adding -DDIG_SIGCHASE is useful to perform DNSSEC validation without resorting to query a validating resolver. (see man page, options +sigchase and +trusted-key) Reproducible: Always
This problem has been fixed in our software repository. The fix will be available on the mirrors soon. Thank you for your bug report. Affected versions: bind-tools-9.4.3_p5-r1, bind-tools-9.6.2_p2-r1, bind-tools-9.7.1-r1, bind-tools-9.7.2_p2-r1. Thanks!
Uhm, it doesn't seem to be working for me (bind-tools-9.7.2_p2-r1). $ dig +dnssec +sigchase isc.org. A Invalid option: +sigchase Usage: dig [@global-server] [domain] [q-type] [q-class] {q-opt} {global-d-opt} host [@local-server] {local-d-opt} [ host [@local-server] {local-d-opt} [...]] Use "dig -h" (or "dig -h | more") for complete list of options
Should be really fixed now, thanks!