validate: fails to accept some correct proofs in deeper NSEC zones
Real-life example: _domainkey.bronz.cz
- it's an empty non-terminal covered by
*.bronz.cz. 3589 IN NSEC arcz._domainkey.bronz.cz. CNAME RRSIG NSEC
Note: aggressive cache does generate the proof correctly, if the record is in cache; it's just validator not accepting it. In real life this issue will probably be rarely causing problems, moreover NODATA isn't often recognizable from SERVFAIL.