Structured logging for DNSSEC key events
During RIPE 75 conversatinos, it came up that users are interested in ability to specify custom hook which gets called when key state changes. Prime example is publishing a new KSK, which would allow them to push a new DS to parent using mechanism they already have.
Details need to be worked out.
Note for docs: Users might want to use this together with their monitoring system so new keys do not get pushed until clients actually can see them (think of hidden masters etc.).
Edited by Daniel Salzman