Marcus, please read:

The security considerations section is extensive and covers all of your
concerns.  OE does not replace VPN out of the box.  

The Win2K system is *NOT* scalable outside of an Enterprise. That's
par for the course for Microsoft - they think about enterprises as their
biggest problem, and never the Internet as a whole.

I suggest that you go and actually setup Opportunistic Encryption before
you go any further. 

DNSSEC has a ways to go to be universally deployed, yes. PowerDNS says
they will implement. Dan Bernstein likely will do so eventually as well
(despite his rants). 

But, you don't need DNSSEC if you are dealing zones you control only
and static IPs. You just secondary all zones onto each gateway. This is
a LOT simpler and WAY more scalable then doing the same thing with LDAP.

You then put the IPs in question into your "private" food group and you
are done for static IPs. A future revision of Openswan will provide a
new food group for cases where we know that there is DNSSEC. (or rather,
it will be insist on private communication with DNSSEC, or bust)

For dynamic IPs (RW), there are several choices, which I won't go into

