so, as some of you have noticed Patrik and I decided to add a parameter for specifying a separate validity for signatures over DNSKEY. I've implemented this in the signer, but the enforcer and auditor needs more work. matthijs; please review my signer changes. jakob