There are two responsible options for the group to take.

The first is to agree with the Europeans who state that these are =
essential requirements and override Bert on the basis that the =
interoperability results simply do not support his claim.

The second is to shut down DNSSEC completely and immediately: stop =
wasting everyone's time and stop preventing other groups from working on =
this problem.

My vote is for the first approach.

> On Tue, Dec 05, 2006 at 07:43:41AM -0800, Hallam-Baker, Phillip wrote:
> > Absolutely nobody has made the claim that NSEC3 is too=20

> complex to be=20
> > deployed.

> Let me then make the claim that DNSSEC-bis + NSEC3 is so=20
> complex I have serious worries over its reliable=20
> implementability, especially considering the number of corner cases.
> Bert
