kzonecheck - add DNSSEC zone check
I would find it useful if kzonecheck could check DNSSEC zone records:
- checking completeness of signatures
- checking if signatures valid now (optional now + N-days)
- checking completeness of NSEC/NSEC3 chain
- checking if every signature has a valid DNSKEY in the zone
- ...