clarified 322

322. [bug] Queries for KEY RRs are now sent to the parent
server rather than the authoritative one, making
DNSSEC insecurity proofs work in many cases
where they previously didn't.
