Since external DNSKEY records may exist in the unsigned version of the zone (for example DNSKEY records from other providers), handle these RRsets also when copying non DNSSEC records from the unsigned zone database to the signed version.
Since external DNSKEY records may exist in the unsigned version of the zone (for example DNSKEY records from other providers), handle these RRsets also when copying non DNSSEC records from the unsigned zone database to the signed version.