When it is time to generate a new signature (dns_dnssec_sign), rather than create a new one, retrieve it from the SKR.