[ Quoting <johani(a)johani.org> in "Re: [knot-dns-users] Knot DNS 1.3.3..."
]
Hi Miek,
Or not even that.
Look at it this way: assume that in the next week there are keys that should
change state. What happens if you don't invoke the key-manager? Has the keys
changed state or not? Eventually you do invoke it, and if at that point all
the state changes and other stuff happen in the right order then you're fine.
My point is that the keys inside the key-manager act a bit like Heisenberg's
Cat. You only know their state if you invoke the key-manager. So not invoking
it will never cause anything bad to happen because you'll never need the
effect of the changed state until you eventually invoke it.
So you'll only have to invoke the key-manager whenever you want it to sign
something, however often that is depending on your KASP.
You're right.
And leaving the 'S' out of the KASP in this case, there doesn't seem to be
much
configuration state left. The few that do remain can easily be specific on the
command line.
Grtz,
--
Miek Gieben
PGP 3880D0F6