Hi, dnssec-signzone incorrectly leaves NSEC records in a zone when "re-using" the old signed zone when changing from NSEC to NSEC3. The resulting zone file will contain both NSEC and NSEC3 records. Paul