> > one would likely need to start with a different structure > > than ndb/dns currently has to get dnssec. but i think that > > the most of the query logic could be reused. > As I understand it; It is an extension, the base DNS stuff should not > change. > What would need to be changed in ndb, or would looking at the source > be better?
i think your understanding ma be incomplete. dnssec requires that the rrs be chained together in a particular order. and any change to a rr triggers resigning. it may be doable, but i think it would be easier to start with dnssec in mind. - erik