If you really want to automate then use DNS UPDATE w/ TSIG for
everything in the delegation.  If/when DNSSEC takes off this really
is the way for key rollovers to be handled.

