Add trust anchor for the newly signed root zone

Mark Andrews requested to merge marka-add-trust-anchor-for-root-zone into main

When the root zone is loaded the ZONEMD verification checks the DNSKEYS in the root zone against the trust-anchors and these do not match for our root zone instance. We can disable this check in named.conf or add trust-anchors for our root zone.

