The test case for zsk-retired was missing the actual checks. Add
them and fix the set_policy call to expect three keys.
# Zone: zsk-retired.autosign.
#
set_zone "zsk-retired.autosign"
-set_policy "autosign" "2" "300"
+set_policy "autosign" "3" "300"
set_server "ns3" "10.53.0.3"
# The third key is not yet expected to be signing.
set_keyrole "KEY3" "zsk"
set_keystate "KEY3" "STATE_DNSKEY" "rumoured"
set_keystate "KEY3" "STATE_ZRRSIG" "hidden"
+check_keys
+check_apex
+check_subdomain
+dnssec_verify
+check_rrsig_refresh
+
#
# Test dnssec-policy inheritance.
#