Ahem. This is a thread about how *this API* should be designed, not how DNSSEC should be designed. You two have had this discussion on the DNSEXT WG mailing list, if I remember correctly. The result was no changes in the protocol, I believe. --Paul Hoffman