Nevertheless, Knot DNS has includes DNSSEC
functionality that could be
separated ;), but I think you included it based on a survey. So it seems
users want "everything but a kitchen sink" kind of software.
Unfortunatelly, not everything is easily separable. Which is the case of
DNSSEC in combination with DDNS.
We really try to make all the components as lightweight as possible. And there
is no reason to keep an authoritative server and recursor in a one box. That's
why we want these as a two independent pieces.
And BTW, nothing prevents from using Knot DNS without DNSSEC. ;-) The DNSSEC
signing has no impact on the answering. It's just a kind of preprocessor of
the zone, which is run before the zone is exposed.
Jan