On Nov 25, 2013, at 10:38 AM, Joe Abley <jabley@xxxxxxxxxxx> wrote: > Isn't this at least part of the motivation behind DANE? > > (I realise DANE requires moving parts in the client and signatures in the published zone, but it seems odd that it hasn't been mentioned.) Is the DNSSEC root key secure against National Security Letters?