Still not sure what advise I should give to openswan, but to give some
more background on why I'm advocating insecure loopups.

My gut feeling currently tells me (this could of course change of
time :-) ), that there is going to be a difference in "doing a lookup"
and "validating some info (most key-related data) from the DNS".
And the primary reason for this is feedback to the user - if all
the feedback you can give is SERVFAIL, people will turn off DNSSEC and
re-query. If your app. can *show* the data *and* tell it is not secure, you
mimic the current situation with ssl certificates (in browsers).

