Exclude a domain from DNSSEC validation, like Unbound's "domain-insecure".

Fri Apr 27 10:05:49 UTC 2012

Jan-Piet Mens <jpmens.dns at gmail.com> wrote:
> From a Comcast talk at SATIN 2012 I believe they called that a "negative
> trust anchor", and IIRC, the author wanted to publish a draft of its
> operation.


There has been a lot of discussion on the IETF dnsop working group mailing
list: http://www.ietf.org/mail-archive/web/dnsop/current/threads.html

