> Hi,
> I just found quite serious bug in dnssec-signzone :-(.

It's not a bug. It was a deliberate decision to only include
generate DS records when -g is specified. You manage the
transition from secure to insecure by removing the keyset
of the child.

