nCryptographic evidence for the
verifiably insecure zone status
is given by parent
nIf there is no DS record as proved
by a NXT record with valid
signature, the child is not secured
nA child may contain signatures but
these will not be used when
building a chain of trust
nIn RFC2535 the parent has a ÒNULLÓ
key with a signature