When using ldns_zone_sign_nsec3(), if I pass it a keyring having multiple KSK and/or ZSK, it only signs the zone with one of each. Using multiple keys is pretty normal, especially during key rollovers, so it's a necessary thing. So is this a bug? Michael Sheldon Dev-DNS Services GoDaddy.com