[ Quoting <johani(a)johani.org> in "Re: [knot-dns-users] Knot DNS 1.3.3..."
]
  Hi Miek,
 Or not even that.
 Look at it this way: assume that in the next week there are keys that should
 change state. What happens if you don't invoke the key-manager? Has the keys
 changed state or not? Eventually you do invoke it, and if at that point all
 the state changes and other stuff happen in the right order then you're fine.
 My point is that the keys inside the key-manager act a bit like Heisenberg's
 Cat. You only know their state if you invoke the key-manager. So not invoking
 it will never cause anything bad to happen because you'll never need the
 effect of the changed state until you eventually invoke it.
 So you'll only have to invoke the key-manager whenever you want it to sign
 something, however often that is depending on your KASP. 
You're right.
And leaving the 'S' out of the KASP in this case, there doesn't seem to be
much
configuration state left. The few that do remain can easily be specific on the
command line.
Grtz,
--
   Miek Gieben
   PGP 3880D0F6