From Fedora Project Wiki
Can you coordinate with other dns server packages in fedora to support this if they support dnssec? In particular: pdns and maradns are both packaged.
How does this affect dnsmasq? Does it handle dnssec ok? libvirt makes heavy use of it.
I think that "invulnerable" is a little to strong and that it should say something like "greatly hardened"