DNSSEC ISSUE (Msg: Request is not signed)

>       Auth servers don't have to set "ad" when responding. Named does
>       no crypto validation when answering from authoritative data.
>       Workarounds are to use a recursion-only view.

Which is exactly what I do; my authoratative nameservers have a
non-authoratative, resolving view listening on the loopback interface
that does do the crypto validatation so that OpenSSH can get validated

I'm curious as to why this is set up this way, though. Wouldn't it make
sense that authoratative servers, when loading or fetching the zone
file, validate the data when loaded and then return responses with the
AD bit set?

