Is there documentation anywhere for enabling "front-signing" (manage dnssec for a zone that is slaved from a dnssec-less master). Or is it as simple as just using secure-zone on a slave zone? Ask