If we accept DNS spoofing would be very bad for ENUM and
telephony-like services in general, it follows that DNSSEC has to be
deployed to prevent those spoofing attacks. There's nothing else which
can solve that problem any time soon. That's why I strongly support
the inclusion of DNSSEC in trials. This stuff needs to be evaluated
so triallists can gain operational experience in handling signing
policies, key management and so on.
Inclusion in trials fine its just not the highest priority IMHO...
hopefully a Phase 2 after some other things are cleared up first.