The 'dnssec-keygen' tool now allows the options '-k <dnssec-policy>' and '-f <flags>' together to create keys from a DNSSEC policy that only match the given role. Allow setting '-fZ' to only create ZSKs, while '-fK' will only create KSKs.