Distinguishing between parent and DLV sigs

Phil Mayers p.mayers at imperial.ac.uk
Mon Oct 7 13:00:06 UTC 2013

I know DLV probably won't live forever, but lookaside zones might for 
some time.

It doesn't look as it bind distinguishes between a signature in the 
parent, or a signature in DLV (with "dnssec-lookaside auto"). Am I 
missing something?

If I'm not, could the log message:

validating X: ZONE RR got insecure response;parent indicates it should 
be secure

...be disambiguated? Maybe:

[parent|<lookaside zone>] indicates it should be secure

Version is 9.9.3-rpz2+rl.13204.02-P2

