In the rush to close down the ITAR you are also cutting off all the
validators that don't support RSASHA256.  The ITAR provides a secure
path to learn the trust anchors of the non RSASHA256 signed TLD's
for those validators.

