Randy: > but is it clear how to integrate into, for example, dnssec and rpki? http://www.iana.org/assignments/dns-sec-alg-numbers/dns-sec-alg-numbers.xhtml The algorithm identifier is assigned. We know how to sign a zone with more than one algorithm. Today, we see some zones signed with RSA and ECDSA, so the same concept should apply. Russ