> From: Florian Weimer <fw at deneb.enyo.de> > Date: Sun, 04 Oct 2009 16:27:51 +0000 > ... > Does this mean that there are no security-aware, validating DNSSEC > resolvers which set DO=1 only when necessary? as far as i know, it is always necessary to set DO=1.