Add a test case to the dnssec system test to check that: - a zone with a prepublished key is only signed with the active key. - a zone with an inactive key but valid signatures retains those signatures and does not add signatures from successor key. - signatures are swapped in a zone when signatures of predecessor inactive key are within the refresh interval.