The dnssec-keygen command for the ZSK generation for the zone multisigner-model2.kasp was wrong (no ZSK was generated in the setup script, but when 'named' is started, the missing ZSK was created anyway by 'dnssec-policy'.