Add a regression test case for the scenario where a secure chain of trust includes an inactive KSK, that is a KSK that is not signing the DNSKEY RRset. (cherry picked from commit f0bfd276e0)
f0bfd276e0