- handle zones with no keys that have the SEP bit.
- warn on all domains where parent has a non-empty DS bit that does
not match ours, even if we did not expect it to have one at all.
+ * dsa-check-zone-rrsig-expiration-many:
+ - expect dnssec by default now.
+ * dsa-check-zone-rrsig-expiration:
+ - in the OK message, clarify we only check sigs at the zone apex.
-- Peter Palfrader <weasel@debian.org> Tue, 23 Apr 2013 20:12:09 +0200