>The goal is to have DNSSEC validation in a system-wide, dedicated code,
>trusted for that purpose; i.e. unbound does DNSSEC validation for
>every application, with a centralized configuration and cache,
>so no application needs or should do this on its own; it can simply
> consult the AD bit in the reply.
