>> Does this mean that there are no security-aware, validating DNSSEC
>> resolvers which set DO=1 only when necessary?

Not positive, but I think Nominum's product only sets DO=1 if DNSSEC  
is configured.

> as far as i know, it is always necessary to set DO=1.

Well, if you can guarantee (or feel comfortable not guaranteeing) that:

a) you are not the target of a forwarder
b) none of the stubs you are serving are going to request DNSSEC- 
related RRs (or perhaps expect those RRs to be validated and cached)

then it is perfectly fine to set DO=0.

Needless to say, it came as a surprise to me when I discovered that it  
was not possible to clear DO without recompiling code.  It was  
certainly not my intent when I wrote 3225.


