>> Not exactly.  By convention we split ZSK and KSK duties, but that's not actually enforced by the resolver.
> Sure, but it is enforced by the current RZ key management process. ICANN can not sign an arbitrary RRset unless several key components are modified, including the DPS and the software used for signing.

The latter part seems interesting to me. Is this written down anywhere where the rest of us can view it? There may be other things in such a document that might help this discussion.

