<div dir="ltr">On Thu, Oct 3, 2013 at 5:42 PM, Mark Andrews <span dir="ltr"><<a href="mailto:marka@isc.org" target="_blank">marka@isc.org</a>></span> wrote:<br><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
Use a DNAME record. That works with DNSSEC.<br>
<br></blockquote><div><br></div><div>Thanks for the suggestion. I would use DNAME, except the old namespace will still have names under it, and names are not allowed to exist below a DNAME. In other words, we're not replacing the old namespace, we're just minimizing its scope and use.<br>
<br>Casey<br></div></div></div></div>