Name Resolution with DNSSEC verification Ideal Assumption having root zone's DNSKEY (and assume/hope most zones below are signed) Reality is... root is not signed nor are most others We need a small start approach DNSSEC security roots begin with some known signed zones also need 'dnssec-enable yes;'