Local BIND named DNS server installed on a virtual host stopped resolving queries through a forwarder resulting in the long list of log lines (
/log/var/messages) similar to this:
Dec 12 17:51:01 master named: error (no valid RRSIG) resolving 'com/DS/IN': 192.168.122.1#53 Dec 12 17:51:01 master named: validating @0x7fce3c2789a0: com DS: no valid signature found
The reason was incorrect time on the virtual host. The solution is the same as for the problem described here: BIND_named:_error_(broken_trust_chain)_resolving_'example.com/A/IN'.