Update the ARM to mention the new built-in "insecure" policy. Update the DNSSEC guide recipe "Revert to unsigned" to add the additional step of reconfiguring the zone to "insecure" (instead of immediately set it to "none").
Update the ARM to mention the new built-in "insecure" policy. Update the DNSSEC guide recipe "Revert to unsigned" to add the additional step of reconfiguring the zone to "insecure" (instead of immediately set it to "none").