Just to avoid any confusion: Although I demonstrated the issue by running BIND on my laptop only, the real usage scenario is resolver service for a few million distinct administrative domains (aka "customers"). Changing the trust anchor is not an option.
Bjørn _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop