FWIW, we've had a large key set for quite a while.  No reports of 
problems from the outside, and no measurable impact on performance on 
the inside.  Until I mentioned it, no one seemed to notice we had 5 
keys. ;)

I'm willing to take reports of problems to our internal service desk. 
In the absence of any, I'm less inclined to worry about message size 
and TCP fallback than before.

DNSSEC is new.  The scary part is that we still don't know what to fear.

