When transitioning from NSEC3 to NSEC the added records where not being signed because the wrong time was being used to determine if a key should be used or not. Check that these records are actually signed.