Why DS
Key management is hard with current DNSSEC.
When zone-keys are rolled-over, the apex keyset changes.
When keyset changes, parent needs to be involved every time.
Keys are rolled over regularly
? Frequent interaction is unwanted by both parent and child