SIGN IN SIGN UP

- Fix that the aggressive negative cache does not insert NSEC

records with overreaching next owner name. Also the result
  is not above the trust anchor's bailiwick. Also RRSIGS are
  not considered valid when an NSEC next owner name is not
  under the signer zone name. Thanks to Qifan Zhang, Palo
  Alto Networks, for the report.
W
W.C.A. Wijngaards committed
5eb362a6c0da075fbf810c7247fc2cdbe50bc6e0
Parent: 0735cb2