we sign everything with NSEC3 but that is our local
policy I think
it makes more sense for the default to be NSEC but with the change to
be easy.
Brett, it will be very easy to change the policy. We just want to
provide some safe defaults for people who want to enable DNSSEC with
a single switch.
Jan