DNSSEC: Complete support for key delegations to sub-domains
- key-delegate script for constructing DS record sets in dss/*
- DS macro for importing DS record sets to zones
- DSFOR macro for adding dependencies on DS record sets to Makefile
- key-update does not choke on empty directories
- resign-stamp moved back to keys, so that it is not deleted by key
hash cleanups
- dnssec-signzone cannot be told to skip creation of dsset files,
so redirect them from current directory to tmp/
- terminology: domain vs. zone