in practice the DNSSEC option is provided in many cases, considering the common default behavior of widely deployed resolvers, while not many zones are actually not signed at all in the first place (much less whether it's NSEC or NSEC3). so in many cases we should simply be able to stop the condition check with the nsec_signed.
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|