DNSSEC: impacts Zones become larger need periodic maintenance have to deal with key management Resolvers need to know Secure Entry Points to signed sub trees. Changes over time, needs updating. Only few implementations support. BIND-9, DNSJava, Net:DNS, NDS, ANS, CNS |