Creating the KSR happens on the "ZSK side". The KSK is offline and while the public key and state file may be present, draft-icann-dnssec-keymgmt-01.txt suggest that the KSR only contains ZSKs. This is also what knot dns does, so it would also be in the spirit of interoperability.