Also the ICANN's rule for signed TLD delegation for new gTLD is so that delegations from those zones can be signed. It is not so that NXDOMAINS are secure or else NSEC3 with OPTOUT would be banned. There are lots of insecure answers from the new TLDs including delegations. Only those using NSEC or NSEC3 without OPTOUT are secure.
Alt doesn't have any delegations. There is no reason for it to be signed. There is no reason for ICANN to object other than religious arguments. Technically they don't have a leg to stand on. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop