'dnssec-validation yes' should fail when no trust anchors are configured
Using the 'dnssec-validation yes' option now requires an explicitly confgiured 'trust-anchors' statement (or 'managed-keys' or 'trusted-keys', both deprecated).
Closes #4373 (closed)