teor:
- OfflineMasterKey setting (0/1)
- SigningKeyLifetime
- Sandbox (0/1)
Yes, these are directly related to relay security, so if they can be linked to the relay, they should be opt-in.
I added your note to Sebastian's ticket about publishing key expiry information in descriptors. I like Sebastian's idea but I also agree to your opt-in remark - which means that we will likely not get much data at all (how many relay operators will opt-in vs. the effort to make that possible).