The DANE working group has specified 'full certificate' associations, but we do not support those yet. No solutions investigated yet. Related to issue 1 (https://github.com/os3sec/Extended-DNSSEC-Validator/issues/#issue/1)