Now that inline-signing is ignored when there is no dnssec-policy, add 'dnssec-policy default;' to the zones when attempting to add them via 'rndc addzone'.