These NS can't be authoritative since we have a CNAME answer for
which only the record describing that alias is necessarily
authoritative.
But if we allow the current auth, which might be serving the child
zone, to raise the TTL of non-authoritative NS in the cache, they
might be able to keep a "ghost" zone alive forever, even after the
delegation is gone from the parent.
So let's just do nothing with them, we can fetch them directly if
we need them.