- expect dnssec by default now.
* dsa-check-zone-rrsig-expiration:
- in the OK message, clarify we only check sigs at the zone apex.
+ * dsa-check-dnssec-delegation:
+ - accept any ds/dnskey combination whose intersection is not empty.
+ (previously we required them to match exactly.)
-- Peter Palfrader <weasel@debian.org> Tue, 23 Apr 2013 20:12:09 +0200