Yes, generally you should always use the new web.config
Unfortunately there is no way around the maintenance required for machine key, you will always need to do that manually to ensure the machine key never changes. user.config only works for the <appSettings section
Best,
Joe