nThe parent
delegates authority to sign DNS RRs to the
child using this RR
n
nDS is a pointer to the next key in the chain of
trust
uYou may trust data that is signed using a key
that the DS points to
n
nNew RR to solve problems with key-rollovers
uMore on that later