before marking it as insecure. One set of conditions
that can trigger this occurs naturally when rolling
DNSKEY algorithms. [RT #22309]
Had to adjust the test to use RSAMD5 -> RSASH1 as we need to use algorithms
supported by 9.4.